CVE-2022-28889

4.3MEDIUM

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

Опубликовано: 7/7/2022Обновлено: 11/21/2024

Описание

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

ИИ-АнализНа базе ИИ

Затронутые продукты

apachedruid

Ссылки