department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
283 stars 204 forks source link

[Pen-Test] Medium Finding 25114 - ClickJacking Attack -- Due 7/10 #80990

Closed kenmayo closed 3 months ago

kenmayo commented 6 months ago

Please resolve this finding NLT 7/10/24

image.png image.png
hgbarreto commented 4 months ago

Initial Configuration checks on likely sources of this vulnerability indicate proper configuration for most EC2 instances. The XFRAME headers are being explicitly added with the SAMEORIGIN option or the DENY option. In some cases, HTTP to HTTPS redirects cover the vulnerability regardless for the port 80 since it forces the use of HTTPS, making the call respect the XFRAME headers. Will verify the legacy proxies just in case. Will also verify the cluster web services as well.

hgbarreto commented 4 months ago

Team has decided to request a new scan due to the potential of having this vulnerability addressed already. The infrastructure has changed drastically since this scan was performed.

hgbarreto commented 3 months ago

Scan that was requested will take a while.

hgbarreto commented 3 months ago

Closing