{"id":"CVE-2021-42357","details":"When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.","aliases":["GHSA-vv38-4xcj-q4rw"],"modified":"2026-07-09T00:37:25.572540Z","published":"2022-01-17T20:15:07.697Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2022/01/17/2"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/b7v5dkpyqb51nw0lvz4cybhgrfhk1g7j"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/knox","events":[{"introduced":"0"},{"fixed":"6060a757389b16f6fc8c6689503107d0c06a2f1d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.6.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:knox:*:*:*:*:*:*:*:*"}}],"versions":["v1.6.0-release","v1.6.0-RC4","v1.6.0-RC3","v1.6.0-RC2","v1.6.0-RC1","v1.5.0-branch","v1.4.0-branch","v1.3.0-branch","v1.2.0-branch","v1.1.0-branch","v1.0.0-branch","v0.13.0-branch","v0.12.0-branch","v0.11.0-branch","v0.10.0-branch","v0.9.0-branch","v0.8.0-branch","v0.7.0-branch","v0.6.0-branch","v0.5.0-branch","v0.4.0-branch","v0.3.0-branch","v0.2.0-branch","v0.2.0-rc2","v0.2.0-rc1","v0.1.0-m1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-42357.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}