Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-19741

Port CSRF prevention filter (HBASE-15187) to the HBase Thrift server

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • security, Thrift
    • None

    Description

      Our thrift server is prone to the same CSRF issue described in HBASE-15187. Even it only affects browsers it triggers a positive match in some venerability scanners even there is no real impact. We should correct our headers in the HBase Thrift server to avoid that problem.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              esteban Esteban Gutierrez
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated: