Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08035
HistoryJan 18, 2022 - 12:00 a.m.

Apache Knox SSO Cross-Site Scripting Vulnerability

2022-01-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
vulnerability
apache knox
sso
cross-site scripting
web ui
cluster
url parsing error
redirect
request parameters
attacker-controlled page
xss
phishing campaign
cnvd

EPSS

0.002

Percentile

65.0%

Knox Sso is a security vulnerability in Apache Knox SSO, used by the Apache Foundation to provide Web Ui Sso (single sign-on) functionality to your cluster, which stems from a URL parsing error that could craft requests to redirect users to malicious pages. A request containing specially crafted request parameters could be used to redirect users to an attacker-controlled page. This URL needs to be presented to the user outside of the normal request stream via an XSS or phishing campaign. No detailed vulnerability details are currently available.

EPSS

0.002

Percentile

65.0%