Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4958

Опубликовано: 02 июн. 2022
Источник: redhat
CVSS3: 6.1

Описание

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat Advanced Cluster Security 4.2advanced-cluster-security/rhacs-main-rhel8FixedRHSA-2023:520618.09.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1021
https://bugzilla.redhat.com/show_bug.cgi?id=1990363stackrox: Missing HTTP security headers allows for clickjacking in web UI

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

CVSS3: 6.1
github
около 2 лет назад

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

6.1 Medium

CVSS3