CVE-2021-32828

CVSS V2 None CVSS V3 None
Description
The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Site Scripting (XSS). This XSS can be escalated to Remote Code Execution (RCE) by levering the automation API.
Overview
  • CVE ID
  • CVE-2021-32828
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-05T23:15:09
  • Last Modified Date
  • 2023-01-11T20:40:08
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:hyland:nuxeo:*:*:*:*:*:*:*:* 1 OR 11.5.109
History
Created Old Value New Value Data Type Notes
2023-01-05 23:16:49 Added to TrackCVE
2023-01-05 23:16:49 Weakness Enumeration new
2023-01-06 00:26:32 2023-01-05T23:20:46 CVE Modified Date updated
2023-01-06 00:26:32 Received Awaiting Analysis Vulnerability Status updated
2023-01-10 18:20:21 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-12 05:16:04 2023-01-11T20:40:08 CVE Modified Date updated
2023-01-12 05:16:04 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-12 05:16:12 Weakness Enumeration update
2023-01-12 05:16:14 CPE Information updated