CVE Published: 12/12/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Advanced Cluster Security 4.2 Status : PUBLISHED
CVE-2023-4958 Description
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user\'s account permissions to perform other actions.