Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10743

Опубликовано: 27 янв. 2020
Источник: redhat
CVSS3: 3.1

Описание

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.

Отчет

This CVE relates specifically to OpenShift Container Platform's distribution of Kibana. Upstream Kibana don't consider this a vulnerability, but may address this in a future version: https://github.com/elastic/kibana/issues/52809

Меры по смягчению последствий

Any Kibana version with this commit [1] can add the following configuration option to mitigation the problem: config/kibana.yml: server.customResponseHeaders: {"x-frame-options":"deny"} or server.customResponseHeaders: {"x-frame-options":"sameorigin"} [1] https://github.com/elastic/kibana/pull/13045

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5FixedRHSA-2020:372716.09.2020
Red Hat OpenShift Container Platform 4.6openshift4/ose-logging-kibana6FixedRHSA-2020:429827.10.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1834550kibana: X-Frame-Option not set by default might lead to clickjacking

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.

CVSS3: 4.3
debian
больше 4 лет назад

It was discovered that OpenShift Container Platform's (OCP) distributi ...

CVSS3: 4.3
github
больше 3 лет назад

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.

3.1 Low

CVSS3