Uploaded image for project: 'Hadoop YARN'
  1. Hadoop YARN
  2. YARN-10833

RM logs endpoint vulnerable to clickjacking

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      The /logs endpoint is missing the X-FRAME-OPTIONS in the response header, even though YARN is configured to do include it. This makes it vulnerable to clickjacking.

      Request URL: http://{{rm_host}}:8088/logs/
      Request Method: GET
      Status Code: 200 OK
      Remote Address: [::1]:8088
      Referrer Policy: strict-origin-when-cross-origin
      
      HTTP/1.1 200 OK
      Date: Fri, 25 Jun 2021 17:38:38 GMT
      Cache-Control: no-cache
      Expires: Fri, 25 Jun 2021 17:38:38 GMT
      Date: Fri, 25 Jun 2021 17:38:38 GMT
      Pragma: no-cache
      Content-Type: text/html;charset=utf-8
      X-Content-Type-Options: nosniff
      X-XSS-Protection: 1; mode=block
      Content-Length: 469 
      

      Attachments

        1. YARN-10833.001.patch
          10 kB
          Benjamin Teke
        2. YARN-10833.002.patch
          11 kB
          Benjamin Teke

        Issue Links

          Activity

            People

              bteke Benjamin Teke
              bteke Benjamin Teke
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m