Bug 1250552 (CVE-2015-5178) - CVE-2015-5178 JBoss AS/WildFly: missing X-Frame-Options header leading to clickjacking
Summary: CVE-2015-5178 JBoss AS/WildFly: missing X-Frame-Options header leading to cli...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-5178
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1249105
Blocks: 1250555 1271191
TreeView+ depends on / blocked
 
Reported: 2015-08-05 12:49 UTC by Martin Prpič
Modified: 2021-10-21 00:47 UTC (History)
18 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the EAP Management Console could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Clone Of:
Environment:
Last Closed: 2021-10-21 00:47:35 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:1904 0 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 6.4.4 update 2015-10-15 19:40:00 UTC
Red Hat Product Errata RHSA-2015:1905 0 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 6.4.4 update 2015-10-15 19:38:43 UTC
Red Hat Product Errata RHSA-2015:1906 0 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 6.4.4 update 2015-10-15 19:58:56 UTC
Red Hat Product Errata RHSA-2015:1907 0 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 6.4.4 jboss-ec2-eap update 2015-10-15 19:28:38 UTC

Description Martin Prpič 2015-08-05 12:49:03 UTC
It was reported that the EAP console is vulnerable to clickjacking attacks because it does not set the X-Frame-Options HTTP header. An attacker could use this flaw to embedded the EAP console in a web page using a frame or iframe, and then trick a user into performing arbitrary actions in the console.

Comment 6 errata-xmlrpc 2015-10-15 15:28:57 UTC
This issue has been addressed in the following products:

  JBEAP 6.4.z for RHEL 6

Via RHSA-2015:1907 https://rhn.redhat.com/errata/RHSA-2015-1907.html

Comment 7 errata-xmlrpc 2015-10-15 15:42:41 UTC
This issue has been addressed in the following products:

  JBEAP 6.4.z for RHEL 6

Via RHSA-2015:1905 https://rhn.redhat.com/errata/RHSA-2015-1905.html

Comment 8 errata-xmlrpc 2015-10-15 15:43:47 UTC
This issue has been addressed in the following products:

  JBEAP 6.4.z for RHEL 5

Via RHSA-2015:1904 https://rhn.redhat.com/errata/RHSA-2015-1904.html

Comment 9 errata-xmlrpc 2015-10-15 16:00:03 UTC
This issue has been addressed in the following products:

  JBEAP 6.4.z for RHEL 7

Via RHSA-2015:1906 https://rhn.redhat.com/errata/RHSA-2015-1906.html


Note You need to log in before you can comment on or make changes to this bug.