A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Sep 2024 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server. | A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server. |
MITRE
Status: PUBLISHED
Assigner: SolarWinds
Published: 2021-10-29T13:32:18.489198Z
Updated: 2024-09-16T22:50:51.483Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35237
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-29T14:15:07.607
Modified: 2024-11-21T06:12:07.543
Link: CVE-2021-35237
Redhat
No data.