MEDIUM
Clickjacking in the web console
Published Jul 7, 2022
4.3
MEDIUMCVSS 3.1
EPSS 1.87%
Description
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=0.22.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Druid | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to Druid 0.23.0 or later.
Weaknesses (1)
References (3)
- https://github.com/advisories/GHSA-pgq7-jcj5-xx6h Advisory
- https://lists.apache.org/thread/t3nsq4crdr8wqgmj721d2wg6pf26s5cw x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28889
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-pgq7-jcj5-xx6h | Advisory | |
| https://lists.apache.org/thread/t3nsq4crdr8wqgmj721d2wg6pf26s5cw | x_refsource_MISCMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-28889 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 7, 2022
Updated Aug 3, 2024
Reserved Apr 9, 2022
Link CVE-2022-28889
CISA Vulnrichment
GHSA-PGQ7-JCJ5-XX6H Updated n/a