Home
LOW: 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
<1.0.19
affected
Description
HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.
Problem types
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
Product status
<1.0.19
References
support.hcl-software.com/...rticle&sysparm_article=KB0127331