-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Highest
-
None
-
Affects Version/s: No-Version
-
Component/s: Apps - Confluence Questions
-
Severity 3 - Minor
NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.
We received an external security report from Monendra Sahu that https://answers.atlassian.com/ is vulnerable to clickjacking. This can be fixed by sending a X-Frame-Options header with a value of SAMEORIGIN. This will prevent answers from being displayed in frames on other websites, see https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options for more information.
- relates to
-
CONFCLOUD-46884 Implement clickjacking protection on https://answers.atlassian.com/
-
- Closed
-