Aihua Xu created HIVE-17679: ------------------------------- Summary: http-generic-click-jacking for WebHcat server Key: HIVE-17679 URL: https://issues.apache.org/jira/browse/HIVE-17679 Project: Hive Issue Type: Bug Components: WebHCat Affects Versions: 2.1.1 Reporter: Aihua Xu Assignee: Aihua Xu
The web UIs do not include the "X-Frame-Options" header to prevent the pages from being framed from another site. Reference: https://www.owasp.org/index.php/Clickjacking https://www.owasp.org/index.php/Clickjacking_Defense_Cheat_Sheet https://developer.mozilla.org/en-US/docs/Web/HTTP/X-Frame-Options -- This message was sent by Atlassian JIRA (v6.4.14#64029)