Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
None
-
None
-
None
Description
implement the X-Frame-Options for Falcon UI: DENY header in response.
For security this should be implemented to prevent potential security issue allowing click-jacking.
1. Access Falcon UI via curl or browser.
2. Check for X-Frame-Options in the Response Header.