This repository has been archived by the owner on Oct 21, 2022. It is now read-only.
Frameable response (potential Clickjacking) #23
Labels
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-moderate
Security issues with a moderate impact
Milestone
The application surf-dev2.edubadges.nl fails to set an appropriate X-Frame-Options or Content-Security-Policy HTTP header, it is possible for a page controlled by an attacker to load it within an iframe.
The text was updated successfully, but these errors were encountered: