6.1
CVSSv3

CVE-2023-4958

Published: 12/12/2023 Updated: 03/05/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an malicious user to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat advanced cluster security 3.0

redhat advanced cluster security 4.0