PT-2023-18916 · Hcl · Hcl Bigfix Osd Bare Metal Server

CVE-2023-23343

·

Publicado

2023-06-22

·

Atualizado

2023-07-03

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix OSD Bare Metal Server versions 311.12 and earlier
Description A clickjacking issue allows an attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page, resulting in a redirect to an attacker-controlled domain.
Recommendations For HCL BigFix OSD Bare Metal Server versions 311.12 and earlier, update to a version higher than 311.12 to resolve the issue. As a temporary workaround, consider implementing additional validation on user interactions to minimize the risk of clickjacking attacks.

Correção

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23343

Produtos afetados

Hcl Bigfix Osd Bare Metal Server