diff options
author | Kai Blin <kai@samba.org> | 2013-01-18 23:11:07 +0100 |
---|---|---|
committer | Karolin Seeger <kseeger@samba.org> | 2013-01-29 09:48:08 +0100 |
commit | 71225948a249f079120282740fcc39fd6faa880e (patch) | |
tree | 5b950ae37dfa9068fe08d4401e8bd42b63d87b51 /source3/libnet | |
parent | 184d5ab26a553ca7ef3f529e90e4dd8c9aded75d (diff) | |
download | samba-71225948a249f079120282740fcc39fd6faa880e.tar.gz |
swat: Use X-Frame-Options header to avoid clickjacking
Jann Horn reported a potential clickjacking vulnerability in SWAT where
the SWAT page could be embedded into an attacker's page using a frame or
iframe and then used to trick the user to change Samba settings.
Avoid this by telling the browser to refuse the frame embedding via the
X-Frame-Options: DENY header.
Signed-off-by: Kai Blin <kai@samba.org>
Fix bug #9576 - CVE-2013-0213: Clickjacking issue in SWAT.
Diffstat (limited to 'source3/libnet')
0 files changed, 0 insertions, 0 deletions