PT-2022-21400 · Red Hat · Openshift

Sage Mctaggart

·

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-3260

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned.
Description The issue is related to the absence of the X-FRAME-OPTIONS header in response headers, which helps prevent Clickjacking attacks. Without this header, some browsers may interpret the results incorrectly, allowing clickjacking attacks to occur.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-3260

Affected Products

Openshift