CVE-2021-42357
Published Jan 17, 2022When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially craft…
Vendor/product archive
2 CVEs tagged to apache / knox — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially craft…
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. T…