← Vulnerability feed

Vulnerability record · CVE-2023-4958 · published 12 December 2023

CVE-2023-4958: Redhat advanced cluster security clickjacking vulnerability

Redhat · Advanced Cluster Security

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

6.1 CVSS 3.1 Medium EPSS 0.63% · top 51.7% CWE-1021 · Clickjacking
6.1CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed8.8CVE-2022-1902Redhat advanced cluster security exposure of resource to wrong sphere vulnerabilityA flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw …EPSS 1.4%7.8CVE-2024-0406Mholt archiver path traversal vulnerabilityA flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…EPSS 0.93%7.7CVE-2026-44495Axios code injection vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…EPSS 1.0%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 94%analysed5.4CVE-2025-5198Redhat advanced cluster security cross-site scripting vulnerabilityA flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2023-4958), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.