"value":"In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Improper Neutralization of Special Elements used in a Command ('Command Injection')",
"cweId":"CWE-77"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"n/a",
"product":{
"product_data":[
{
"product_name":"rhacs-main-container",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"affected"
}
}
]
}
}
]
}
},
{
"vendor_name":"Red Hat",
"product":{
"product_data":[
{
"product_name":"Red Hat Advanced Cluster Security 4.2",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"4.2.0-6",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat Advanced Cluster Security 3",