-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Highest
-
Component/s: Integrations - Confluence Questions
-
Severity 3 - Minor
NOTE: This bug report is for Confluence Cloud. Using Confluence Server? See the corresponding bug report.
We received an external security report from Monendra Sahu that https://answers.atlassian.com/ is vulnerable to clickjacking. This can be fixed by sending a X-Frame-Options header with a value of SAMEORIGIN. This will prevent answers from being displayed in frames on other websites, see https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options for more information.
- is related to
-
CONFSERVER-46884 Implement clickjacking protection on https://answers.atlassian.com/
-
- Closed
-