Lucene search

K
osvGoogleOSV:CVE-2021-32828
HistoryJan 05, 2023 - 11:15 p.m.

CVE-2021-32828

2023-01-0523:15:09
Google
osv.dev
5
nuxeo
oauth2
xss
rce
api
security

EPSS

0.001

Percentile

46.6%

The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the oauth2 REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.

EPSS

0.001

Percentile

46.6%

Related for OSV:CVE-2021-32828