Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwhh-cc56-qr9m

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.1

Описание

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control. 

This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control. 

This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
nvd
23 дня назад

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface under the attacker's control.  This issue affects all versions of Paragon Automation (Pathfinder, Planner, Insights) before 24.1.1.

EPSS

Процентиль: 8%
0.00031
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-1021