CVE-2021-28113

MEDIUM

Okta Access Gateway <2020.9.3 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.okta.com/security-advisories/cve-2021-28113

Scores

CVSS v3 6.7
EPSS 0.2233
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Details

CWE
CWE-78
Status published
Products (1)
okta/access_gateway < 2020.8.4
Published Apr 02, 2021
Tracked Since Feb 18, 2026