Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-21902

HiveServer2 UI: jetty response header needs X-Frame-Options

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 3.1.0
    • 4.0.0-alpha-1
    • None
    • Reviewed

    Description

      there are some vulnerability are reported for hiveserver2 ui

      X-Frame-Options or Content-Security-Policy: frame-ancestors HTTP Headers missing on port 10002.

      GET / HTTP/1.1 
      Host: HOSTNAME:10002 
      Connection: Keep-Alive 
      
      
      
      X-XSS-Protection HTTP Header missing on port 10002. 
      X-Content-Type-Options HTTP Header missing on port 10002. 
      

      after the proposed changes

      HTTP/1.1 200 OK
      Date: Thu, 20 Jun 2019 05:29:59 GMT
      Content-Type: text/html;charset=utf-8
      X-Content-Type-Options: nosniff
      X-FRAME-OPTIONS: SAMEORIGIN
      X-XSS-Protection: 1; mode=block
      Set-Cookie: JSESSIONID=15kscuow9cmy7qms6dzaxllqt;Path=/
      Expires: Thu, 01 Jan 1970 00:00:00 GMT
      Content-Length: 3824
      Server: Jetty(9.3.25.v20180904)
      

      Attachments

        1. HIVE-21902.01.patch
          16 kB
          Rajkumar Singh
        2. HIVE-21902.patch
          15 kB
          Rajkumar Singh

        Activity

          People

            Rajkumar Singh Rajkumar Singh
            Rajkumar Singh Rajkumar Singh
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: