CVE-2023-4958
12.12.2023, 10:15
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | advanced_cluster_security | 3.0 |
redhat | advanced_cluster_security | 4.0 |
𝑥
= Vulnerable software versions
References