Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-22533

Fix possible LLAP daemon web UI vulnerabilities

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 4.0.0-alpha-1
    • llap
    • None

    Description

      Security tools that look for possible vulnerabilities find issues with LLAP daemon web UI:

      • dir listing for images,css,js folders 
      • missing X-Frame-Options response header in the response

      Similarly we should disable dir listing on HS2 web UI /static page too, as it is of no use anyway.

      Attachments

        1. HIVE-22533.0.patch
          11 kB
          Ádám Szita

        Activity

          People

            szita Ádám Szita
            szita Ádám Szita
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: