Details
Alert Id 10020-1
Alert Type Passive Scan Rule
Status release
Risk Medium
CWE 16
WASC 15

Summary

X-Frame-Options header is not included in the HTTP response to protect against ‘ClickJacking’ attacks.

Solution

Most modern Web browsers support the X-Frame-Options HTTP header. Ensure it's set on all web pages returned by your site (if you expect the page to be framed only by pages on your server (e.g. it's part of a FRAMESET) then you'll want to use SAMEORIGIN, otherwise if you never expect the page to be framed, you should use DENY. ALLOW-FROM allows specific websites to frame the web page in supported web browsers).

References

Code

org/zaproxy/zap/extension/pscanrules/XFrameOptionScanRule.java