UI Redressing (Clickjacking)

XMLWordPrintable

      NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      Confluence is vulnerable to Clickjacking. That is, it is possible to frame confluence from a page hosted in a different domain and trick the user into performing an action they did not intend to perform, for example changing their display name.

      This issue can be addressed by using the X-Frame-Options header and or through the CSP frame-ancestors directive. When fixing this issue we need to ensure that resources that need to be able to be framed are still allowed to be framed, e.g. gadget resources.

            Assignee:
            Phong Quoc Le (Inactive)
            Reporter:
            Adrian Bravo
            Votes:
            7 Vote for this issue
            Watchers:
            28 Start watching this issue

              Created:
              Updated:
              Resolved: