First published: Thu Jul 07 2022(Updated: )
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Druid | <0.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28889 is a vulnerability in Apache Druid 0.22.1 and earlier that allows clickjacking attacks.
CVE-2022-28889 affects Apache Druid 0.22.1 and earlier, allowing clickjacking attacks.
Clickjacking is a technique where an attacker tricks a user into clicking on a malicious link disguised as a legitimate website element.
CVE-2022-28889 has a severity score of 4.3, which is considered medium.
To fix CVE-2022-28889, upgrade to Apache Druid 0.23.0 or later, as it includes the necessary headers to prevent clickjacking.