Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3260

Опубликовано: 29 июн. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

Отчет

This is a vulnerability that arises from websites not having X-Frame options HTTP response header. A successful exploitation of this vulnerability would result in a clickjacking attack, which not only requires user interaction but also wouldn't result in any loss or damage to integrity, confidentiality, or availability. This, at best, can be used to impersonate your website, which is why Red Hat has assigned this low impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshiftOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1021
https://bugzilla.redhat.com/show_bug.cgi?id=2106780Openshift: Missing X-Frame-Options Header

EPSS

Процентиль: 36%
0.00432
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
почти 4 года назад

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

CVSS3: 4.8
github
почти 4 года назад

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

EPSS

Процентиль: 36%
0.00432
Низкий

6.5 Medium

CVSS3