CVE-2023-4958

Source
https://cve.org/CVERecord?id=CVE-2023-4958
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4958.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4958
Published
2023-12-12T10:02:33.672Z
Modified
2026-07-15T01:49:19.293601766Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L CVSS Calculator
Summary
Stackrox: missing http security headers allows for clickjacking in web ui
Details

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

Database specific
{
    "cwe_ids": [
        "CWE-1021"
    ],
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4958.json"
}
References

Affected packages

Git / github.com/stackrox/stackrox

Affected ranges

Type
GIT
Repo
https://github.com/stackrox/stackrox
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        }
    ],
    "cpe": "cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:kubernates:*:*",
    "source": "CPE_STRING"
}

Affected versions

4.*
4.0
4.0.x

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4958.json"