CVE-2022-28889
published 2022-07-07CVE-2022-28889: In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.74%
75.0th percentile
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | druid | < 0.23.0 | 0.23.0 |
| apache_software_foundation | apache_druid | unspecified – 0.22.1 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Druid before 0.23.0 vulnerable to clickjacking
osv·2022-07-08
CVE-2022-28889 [MEDIUM] Apache Druid before 0.23.0 vulnerable to clickjacking
Apache Druid before 0.23.0 vulnerable to clickjacking
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
GHSA
Apache Druid before 0.23.0 vulnerable to clickjacking
ghsa·2022-07-08
CVE-2022-28889 [MEDIUM] CWE-1021 Apache Druid before 0.23.0 vulnerable to clickjacking
Apache Druid before 0.23.0 vulnerable to clickjacking
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-07
Published