CVE-2023-4958

Publication date

2023-12-12 10:02:33

Family

redhat

State

PUBLISHED

Description

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the users account permissions to perform other actions.