Skip to content

Prevent vicadmin from being loaded in an iframe#8177

Merged
zjs merged 1 commit intovmware:masterfrom
zjs:issue/8174
Aug 7, 2018
Merged

Prevent vicadmin from being loaded in an iframe#8177
zjs merged 1 commit intovmware:masterfrom
zjs:issue/8174

Conversation

@zjs
Copy link
Member

@zjs zjs commented Aug 4, 2018

In order to protect the vicadmin page from being embedded in a page
controlled by an attacker, set the Content-Security-Policy header to
disallow rendering of the page within an iframe.

Fixes #8174


[Group9-VIC-Admin]

@zjs zjs self-assigned this Aug 4, 2018
@zjs zjs requested a review from hickeng August 4, 2018 00:40
@zjs zjs requested a review from a team as a code owner August 4, 2018 00:40
In order to protect the vicadmin page from being embedded in a page
controlled by an attacker, set the Content-Security-Policy header to
disallow rendering of the page within an iframe.
@zjs zjs merged commit 3f68360 into vmware:master Aug 7, 2018
zjs added a commit to zjs/vic that referenced this pull request Aug 7, 2018
In order to protect the vicadmin page from being embedded in a page
controlled by an attacker, set the Content-Security-Policy header to
disallow rendering of the page within an iframe.

(cherry picked from commit 3f68360)
zjs added a commit that referenced this pull request Aug 9, 2018
In order to protect the vicadmin page from being embedded in a page
controlled by an attacker, set the Content-Security-Policy header to
disallow rendering of the page within an iframe.

(cherry picked from commit 3f68360)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants