Security Advisory

CVE-2023-4958

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-12-12 10:02:33
Last updated 2024-08-02 07:44:53
Assigner redhat
State PUBLISHED

Description

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the users account permissions to perform other actions.