Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4958


In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.


Published

2023-12-12T10:15:10.853

Last Modified

2024-11-21T08:36:20.490

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1021
  • Type: Secondary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat advanced_cluster_security 3.0 Yes
Application redhat advanced_cluster_security 4.0 Yes

References