Описание
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into performing unintended actions. Version 0.26.6 patches the issue.
Уязвимые конфигурации
Конфигурация 1Версия до 0.26.6 (исключая)
cpe:2.3:a:dokploy:dokploy:*:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00027
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-1021
EPSS
Процентиль: 7%
0.00027
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-1021