logo

Database

Clickjacking In org.apache.druid:druid

Description

Apache Druid before 0.23.0 vulnerable to clickjacking In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-2O2V4 – Vulnerability | Fluid Attacks Database