Details
-
Bug
-
Resolution: Fixed
-
Low
-
5.1.1
-
None
Description
NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.
Confluence is vulnerable to Clickjacking. That is, it is possible to frame confluence from a page hosted in a different domain and trick the user into performing an action they did not intend to perform, for example changing their display name.
This issue can be addressed by using the X-Frame-Options header and or through the CSP frame-ancestors directive. When fixing this issue we need to ensure that resources that need to be able to be framed are still allowed to be framed, e.g. gadget resources.
Attachments
Issue Links
- duplicates
-
CONFSERVER-22952 Enable X-FRAME-Option in HTTP response headers in order to provide clickjacking protection
- Closed
- relates to
-
CONFCLOUD-29230 UI Redressing (Clickjacking)
- Closed
- supersedes
-
CONFSERVER-22952 Enable X-FRAME-Option in HTTP response headers in order to provide clickjacking protection
- Closed
- is related to
-
SCT-1150 Loading...
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...