CVE-2022-3260
published 2022-12-08CVE-2022-3260: The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results…
PriorityP419medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.43%
35.4th percentile
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenShift Response Header ui layer (EUVD-2022-42662)
vuldb·2026-07-10·CVSS 4.8
CVE-2022-3260 [MEDIUM] OpenShift Response Header ui layer (EUVD-2022-42662)
A vulnerability was found in OpenShift and classified as critical. Affected by this issue is some unknown functionality of the component Response Header Handler. Executing a manipulation can lead to improper restriction of rendered ui layers.
This vulnerability appears as CVE-2022-3260. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-v9rj-m949-r3xx: The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack
ghsa_unreviewed·2022-12-08
CVE-2022-3260 [MEDIUM] CWE-1021 GHSA-v9rj-m949-r3xx: The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
Red Hat
Openshift: Missing X-Frame-Options Header
vendor_redhat·2022-06-29·CVSS 4.8
CVE-2022-3260 [MEDIUM] CWE-1021 Openshift: Missing X-Frame-Options Header
Openshift: Missing X-Frame-Options Header
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
Statement: This is a vulnerability that arises from websites not having X-Frame options HTTP response header. A successful exploitation of this vulnerability would result in a clickjacking attack, which not only requires user interaction but also wouldn't result in any loss or damage to integrity, confidentiality, or availability. This, at best, can be used to impersonate your website, which is why Red Hat has assigned this low impact.
Package: openshift (Red Hat OpenShift Container Platform 4) - Out of support scope
No detection rules found.
No public exploits indexed.
2022-12-08
Published