Back

MEDIUM

Clickjacking in the web console

Published Jul 7, 2022

Description

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

Affected products

Remediation

Vendor solution

Upgrade to Druid 0.23.0 or later.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 7, 2022
Updated Aug 3, 2024
Reserved Apr 9, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-PGQ7-JCJ5-XX6H