
Cloud Vulnerability DB
A community-led vulnerabilities database
KNIME Server before version 4.13.4 contains a DOM-based Cross-Site Scripting (XSS) vulnerability in the old WebPortal login page. The vulnerability was discovered on December 8, 2021 (NVD, Zigrin).
The vulnerability is a DOM-based XSS that exists in the login panel of the KNIME Server web application. It can be exploited by creating a specially crafted URL that, when opened by a victim, allows execution of arbitrary JavaScript code in the victim's browser context. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 HIGH with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L (Zigrin).
If successfully exploited, the vulnerability allows an attacker to execute arbitrary JavaScript code in the victim's browser context. When the victim is an administrator, the vulnerability could be used to create new administrator accounts. The attack requires no authentication to exploit, though authenticated users can also be targeted (Zigrin).
The vulnerability has been fixed in KNIME Server versions 4.13.4, 4.12.5, and 4.12.6. Users are recommended to update to one of these fixed versions (Zigrin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."