Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh4r-593p-f8mr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element.

The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element.

EPSS

Процентиль: 85%
0.02607
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 10 лет назад

The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element.

EPSS

Процентиль: 85%
0.02607
Низкий

Дефекты

CWE-20