Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xrv-7wfr-fxj6

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

EPSS

Процентиль: 9%
0.00033
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021
CWE-77

Связанные уязвимости

CVSS3: 6.1
redhat
больше 3 лет назад

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

CVSS3: 6.1
nvd
около 2 лет назад

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

EPSS

Процентиль: 9%
0.00033
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021
CWE-77