If our public status page is tested against clickjacking it results vulnerable to this kind of attack, due to the lack of X-Frame-Options and CSP HTTP headers. Is there a way to set X-Frame-Options and CSP in HTTP response headers?
Hi @Alessandro Casella ,Thanks for reaching out about this. We do have a feature request for this open right now: STATUS-96. My engineering team is gathering interest on it and might decide to implement it soon. Feel free to reach out via support.atlassian.com if you want more information. Best, - Abraham
Please add this feature. Our site scores a "D" on securityheaders.com and drags down our bitsight rating.
Thanks
Dave
Please add those missing HTTP headers, such as X-Frame and CSP , they are strong OWASP requirements and a good practice in ISO/IEC27001, NIST,..
Please add those missing HTTP headers. This is becoming a significant issue with 3rd party risk assessment, impacting the cost of cyber insurance, and the willingness of customers to engage. It seems trivial, but the tools in the space to assess 3rd party risk are generally based on sampling of available resources and then an overall assessment made based on this sampling. While this may not seem fair, it is becoming the overall approach in this space.
By using statuspage we in essence our reducing our cyber security rating and potentially increasing our cyber insurance costs.
Needed headers:
It looks like you're new here. Sign in or register to get started.