CVE-2022-28889: Clickjacking in the web console
Published Jul 7, 2022
·Updated
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
Affected Software
1 affected component
Apache Druid<0.23.0
Event History
Jul 7, 2022
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-28889?
CVE-2022-28889 is a vulnerability in Apache Druid 0.22.1 and earlier that allows clickjacking attacks.
2
How does CVE-2022-28889 affect Apache Druid?
CVE-2022-28889 affects Apache Druid 0.22.1 and earlier, allowing clickjacking attacks.
3
What is clickjacking?
Clickjacking is a technique where an attacker tricks a user into clicking on a malicious link disguised as a legitimate website element.
4
How severe is CVE-2022-28889?
CVE-2022-28889 has a severity score of 4.3, which is considered medium.
5
How can I fix CVE-2022-28889?
To fix CVE-2022-28889, upgrade to Apache Druid 0.23.0 or later, as it includes the necessary headers to prevent clickjacking.