Protection Mechanism Failure in Kiwi Syslog Server - CVE-2021-35237

 

Protection Mechanism Failure in Kiwi Syslog Server - CVE-2021-35237

Published: November 2, 2021


Vulnerability identifier: #VU57856
CSH Severity: Medium
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35237
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a missing HTTP header (X-Frame-Options). A remote attacker can trick a victim to click on an actionable item, hijack the user activity intended for the original server and send them to the other server.


Affected software

Kiwi Syslog Server

How to mitigate CVE-2021-35237

Install updates from vendor's website.

Kiwi Syslog Server - update to 9.8

External References

Related Security Bulletins