You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jan 7, 2020. It is now read-only.
Particularly in our scans
/bower_components/uchiwa-web/partials/login/ was the page that was scanned and was identified as not having the appropriate response headers.
Running security scans on our Uchiwa deployments we found that the webserver is vulnerable to clickjacking
http://www.nessus.org/u?399b1f56
https://www.owasp.org/index.php/Clickjacking_Defense_Cheat_Sheet
http://en.wikipedia.org/wiki/Clickjacking
Particularly in our scans
/bower_components/uchiwa-web/partials/login/ was the page that was scanned and was identified as not having the appropriate response headers.
Expected Behavior
Webserver should mitigate Clickjacking attacks.
Current Behavior
Missing the remediation for Clickjacking
Possible Solution
There are multiple solutions as outlined here
https://www.owasp.org/index.php/Clickjacking_Defense_Cheat_Sheet
One of the simplest options is to enable the X-Frame-Options response header.
Context
In our security and compliance auditing, we ran security scans using Nessus scanner and identified this as a potential issue.
Your Environment
The text was updated successfully, but these errors were encountered: