CVE-2023-4958
Stackrox: missing http security headers allows for clickjacking in web ui
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.
En Red Hat Advanced Cluster Security (RHACS), se descubrió que faltaban algunos encabezados HTTP relacionados con la seguridad, lo que permitía a un atacante explotar esto con un ataque de clickjacking. Un atacante podría aprovechar esto convenciendo a un usuario válido de RHACS para que visite una página web controlada por el atacante, que apunta engañosamente a endpoints de RHACS válidos, secuestrando los permisos de la cuenta del usuario para realizar otras acciones.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-14 CVE Reserved
- 2023-09-19 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1021: Improper Restriction of Rendered UI Layers or Frames
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1990363 | 2023-09-18 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2023:5206 | 2024-05-03 | |
https://access.redhat.com/security/cve/CVE-2023-4958 | 2023-09-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Advanced Cluster Security Search vendor "Redhat" for product "Advanced Cluster Security" | 3.0 Search vendor "Redhat" for product "Advanced Cluster Security" and version "3.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Advanced Cluster Security Search vendor "Redhat" for product "Advanced Cluster Security" | 4.0 Search vendor "Redhat" for product "Advanced Cluster Security" and version "4.0" | kubernates |
Affected
|