[ https://issues.apache.org/jira/browse/HIVE-22533?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16981536#comment-16981536 ]
Marta Kuczora commented on HIVE-22533: -------------------------------------- +1 Thanks [~szita] for the patch. > Fix possible LLAP daemon web UI vulnerabilities > ----------------------------------------------- > > Key: HIVE-22533 > URL: https://issues.apache.org/jira/browse/HIVE-22533 > Project: Hive > Issue Type: Improvement > Components: llap > Reporter: Ádám Szita > Assignee: Ádám Szita > Priority: Major > Attachments: HIVE-22533.0.patch > > > Security tools that look for possible vulnerabilities find issues with LLAP > daemon web UI: > * *dir listing* for _images,css,js_ folders > * *missing X-Frame-Options response header* in the response > Similarly we should disable dir listing on HS2 web UI /static page too, as it > is of no use anyway. -- This message was sent by Atlassian Jira (v8.3.4#803005)