metrotranscom / doorway

component-based web framework for affordable housing management
Apache License 2.0
3 stars 1 forks source link

Security Risk: Web Page can be Framed #448

Open iph-97 opened 9 months ago

iph-97 commented 9 months ago

Description from Glenn:

Qualys reported a medium level security risk w/ doorway prod. This is the info: The problem: The web page can be framed. This means that clickjacking attacks against users are possible. Note: Only 10 pages are reported for this QID similar to 150245 Missing header: X-Frame-Options Impact Description With clickjacking, an attacker can trick a victim user into clicking an invisible frame on the web page, thereby causing the victim to take an action they did not intend to take. Solution Description Clickjacking prevention mechanisms include:

Exygy next steps:

QA Notes: This will be handled by Eng (specifically @ColinBuyck) testing directly on localhost is proving to be difficult so this QA is a central part of the work for this issue.

sarahlazarich commented 8 months ago
sarahlazarich commented 1 month ago

going to ask Glenn if this is still relevant - partially fixed! Might be ok to close out.