NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      Confluence is vulnerable to Clickjacking. That is, it is possible to frame confluence from a page hosted in a different domain and trick the user into performing an action they did not intend to perform, for example changing their display name.

      This issue can be addressed by using the X-Frame-Options header and or through the CSP frame-ancestors directive. When fixing this issue we need to ensure that resources that need to be able to be framed are still allowed to be framed, e.g. gadget resources.

            [CONFSERVER-29230] UI Redressing (Clickjacking)

            Renata Dornelas made changes -
            Remote Link Original: This issue links to "Page (Atlassian Documentation)" [ 173489 ]
            Mark M made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 930044 ]
            Adam G. made changes -
            Remote Link Original: This issue links to "Page (Confluence)" [ 662276 ]
            Adam G. made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 662276 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 648301 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 646255 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 646176 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 642146 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 638976 ]
            kitkat (Inactive) made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 639113 ]

              ple Phong Quoc Le (Inactive)
              adrian.bravo Adrian Bravo
              Affected customers:
              7 This affects my team
              Watchers:
              28 Start watching this issue

                Created:
                Updated:
                Resolved: