Описание
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:teradici:pcoip_management_console:20.01.1:*:*:*:*:*:*:*
cpe:2.3:a:teradici:pcoip_management_console:20.04:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00197
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-1021
CWE-1021
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.
EPSS
Процентиль: 42%
0.00197
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-1021
CWE-1021