Clickjacking Vulnerability in VMware NSX
search cancel

Clickjacking Vulnerability in VMware NSX

book

Article ID: 413352

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • During a security scan performed with the Burp Suite tool, a "Clickjacking" vulnerability was identified within the NSX application.
  • It was observed that the application's interface can be embedded within an <iframe> or <frame> tag on another website, leaving it susceptible to this type of attack.

  • Severity of Risk: Low
  • Impact: Users may unknowingly be tricked into performing unintended actions such as submitting forms, changing security settings, or initiating transactions

Environment

VMware NSX

Resolution

The recommendation is to set 'X-frame-Options: Deny or Sameorigin'

In versions - NSX 4.2, 9.0, 9.1 the X-frame-Options header configuration is included.