Описание
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
Отчет
This is a vulnerability that arises from websites not having X-Frame options HTTP response header. A successful exploitation of this vulnerability would result in a clickjacking attack, which not only requires user interaction but also wouldn't result in any loss or damage to integrity, confidentiality, or availability. This, at best, can be used to impersonate your website, which is why Red Hat has assigned this low impact.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
EPSS
6.5 Medium
CVSS3