OktaOKTA-15CYJ0A
Okta Access Gateway CVE-2021-28113 - Apr 2, 2021
UnratedCVE-2021-28113 · Published Apr 2, 2021
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway in version 2020.8.4 and earlier allows attackers with admin access to the Okta Access Gateway UI to execute OS commands as a privileged system account.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 12022 | Okta Active Directory Agent CVE-2022-1697 - Sep 1, 2022 | Unrated | No fix yet |
| Mar 212022 | Okta Advanced Server Access Client CVE-2022-1030 - Mar 21, 2022 | Unrated | No fix yet |
| Feb 172022 | Okta Advanced Server Access Client CVE-2022-24295 - Feb 17, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta RADIUS Server Agent CVE-2021-45105 - Jan 26, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta On-Prem MFA Agent CVE-2021-45046 - Jan 26, 2022 | Unrated | No fix yet |
| Jan 262022 | Okta RADIUS Server Agent CVE-2021-45046 - Jan 26, 2022 | Unrated | No fix yet |