CVE-2021-35237: Clickjacking Vulnerability
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35237?
CVE-2021-35237 is a vulnerability that results from a missing HTTP header (X-Frame-Options) in Kiwi Syslog Server, leaving customers vulnerable to clickjacking attacks.
What is clickjacking?
Clickjacking is an attack where an attacker uses a transparent iframe to trick users into clicking on elements that perform unintended actions.
How does CVE-2021-35237 affect Solarwinds Kiwi Syslog Server?
CVE-2021-35237 affects Solarwinds Kiwi Syslog Server version 9.7.2 and earlier by not including the necessary X-Frame-Options HTTP header, making it vulnerable to clickjacking attacks.
What is the severity of CVE-2021-35237?
CVE-2021-35237 has a severity rating of medium with a score of 4.3 out of 10.
How can I mitigate the vulnerability in Kiwi Syslog Server?
To mitigate the vulnerability, upgrade Kiwi Syslog Server to version 9.8 or later, which includes the necessary X-Frame-Options HTTP header to protect against clickjacking attacks.