PT-2021-24156 · Knime · Knime Server

Dawid Czarnecki

·

Published

2021-12-08

·

Updated

2023-09-28

·

CVE-2021-44726

CVSS v3.1

8.8

High

VectorAC:L/AV:N/A:L/C:H/I:L/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions: KNIME Server versions prior to 4.13.4
Description: The issue allows for XSS via the old WebPortal login page.
Recommendations: For versions prior to 4.13.4, update to version 4.13.4 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-44726

Affected Products

Knime Server