{"id":"CVE-2023-4958","summary":"Stackrox: missing http security headers allows for clickjacking in web ui","details":"In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.","modified":"2026-08-12T03:51:18.485915378Z","published":"2023-12-12T10:02:33.672Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4958.json","cna_assigner":"redhat","cwe_ids":["CWE-1021"]},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2023:5206"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-4958"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4958"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1990363"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stackrox/stackrox","events":[{"introduced":"63fce4eb4d89f3a88734d1950a128a02b0abcf74"},{"last_affected":"63fce4eb4d89f3a88734d1950a128a02b0abcf74"}],"database_specific":{"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:kubernates:*:*"}}],"versions":["4.0","4.0.x"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4958.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L"}]}