PT-2023-18916 · Hcl · Hcl Bigfix Osd Bare Metal Server
CVE-2023-23343
·
Publicado
2023-06-22
·
Atualizado
2023-07-03
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HCL BigFix OSD Bare Metal Server versions 311.12 and earlier
Description
A clickjacking issue allows an attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page, resulting in a redirect to an attacker-controlled domain.
Recommendations
For HCL BigFix OSD Bare Metal Server versions 311.12 and earlier, update to a version higher than 311.12 to resolve the issue.
As a temporary workaround, consider implementing additional validation on user interactions to minimize the risk of clickjacking attacks.
Correção
Clickjacking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hcl Bigfix Osd Bare Metal Server