Description
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
Remediation
References
https://lists.apache.org/thread/t3nsq4crdr8wqgmj721d2wg6pf26s5cw
Related Vulnerabilities
CVE-2021-26117 Vulnerability in maven package org.apache.activemq:artemis-server
CVE-2019-10355 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2022-29251 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2021-27644 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server
CVE-2022-33140 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-framework