CVE-2021-40096
SquaredUp vulnerability analysis and mitigation

Overview

A cross-site scripting (XSS) vulnerability was discovered in SquaredUp for SCOM version 5.2.1.6654 and earlier versions. The vulnerability, identified as CVE-2021-40096, was found in the integration configuration component and allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations. The vulnerability was disclosed and documented in December 2021 (NVD, SquaredUp Support).

Technical details

The vulnerability is a stored XSS issue that specifically affects the creation of Azure Active Directory, Azure App Insights, and Azure Log Analytics providers in SquaredUp Dashboard Server. The vulnerability allows attackers to inject malicious content into the application through the authorisationUrl parameter in integration configurations (SquaredUp Support).

Impact

The vulnerability enables attackers to inject and execute arbitrary web script or HTML in the context of the application, potentially affecting users who access the compromised configurations. This could lead to unauthorized access to sensitive information or manipulation of the application's behavior (NVD).

Mitigation and workarounds

The vulnerability has been fixed in SquaredUp Dashboard Server version 5.3.1. Users running affected versions (earlier than 5.3.1) of SCOM Edition, Azure Edition, or Community Edition should upgrade to version 5.3.1 or later to address this security issue (SquaredUp Support).

Community reactions

The vulnerability was responsibly disclosed by Kajetan Rostojek from ING Tech Poland, demonstrating effective collaboration between security researchers and software vendors (SquaredUp Support).

Additional resources


SourceThis report was generated using AI

Related SquaredUp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-40096MEDIUM5.4
  • SquaredUp logoSquaredUp
  • cpe:2.3:a:squaredup:squaredup
NoYesDec 07, 2021
CVE-2021-40094MEDIUM5.4
  • SquaredUp logoSquaredUp
  • cpe:2.3:a:squaredup:squaredup
NoYesDec 07, 2021
CVE-2021-40093MEDIUM5.4
  • SquaredUp logoSquaredUp
  • cpe:2.3:a:squaredup:squaredup
NoYesDec 07, 2021
CVE-2021-40092MEDIUM5.4
  • SquaredUp logoSquaredUp
  • cpe:2.3:a:squaredup:squaredup
NoYesDec 07, 2021
CVE-2021-40095MEDIUM4.9
  • SquaredUp logoSquaredUp
  • cpe:2.3:a:squaredup:squaredup
NoYesDec 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management