Fedora Account System
Red Hat Associate
Red Hat Customer
In RHACS 3.63.0 Ui it was found to be is vulnerable to Clickjacking. This is caused due to missing HTTP headers (X-Frame-Options or Content-Security-Policy) this is helping an attacker to load an iframe and trick the user to click and transferred it into their malformed website.
Upstream fix: https://github.com/stackrox/stackrox/pull/6839
This issue has been addressed in the following products: RHACS-4.2-RHEL-8 Via RHSA-2023:5206 https://access.redhat.com/errata/RHSA-2023:5206