First published: Thu Jun 22 2023(Updated: )
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=311.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23343 is a clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower.
The severity of CVE-2023-23343 is medium with a score of 6.1.
CVE-2023-23343 allows an attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
HCL BigFix OSD Bare Metal Server versions 311.12 or lower are affected by CVE-2023-23343.
To fix CVE-2023-23343, update HCL BigFix OSD Bare Metal Server to a version higher than 311.12.