CVE-2021-23888
Summary
| CVE | CVE-2021-23888 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-26 10:15:00 UTC |
| Updated | 2023-11-07 03:30:00 UTC |
| Description | Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | All | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | - | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_1 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_2 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_3 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_4 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_5 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_6 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_7 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_8 | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.10.0 | update_9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee Security Bulletin - ePolicy Orchestrator update addresses three vulnerabilities (CVE-2021-23888, CVE-2021-23889, CVE-2021-23890) | kc.mcafee.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.