Skip to content
Thomas Young-Audet edited this page Jun 8, 2020 · 4 revisions

TWA-0207

Message

"X-Frame-Options is 'allow-from', consider 'deny' or 'none'"

Explanation

The X-Frame-Options header provide clickjacking protection to your site users by not allowing rendering of a page in a frame. The allow-from directive allows the page to only be loaded in a frame on the specified origin and or domain. This is unsafe and can be abused.

In addition, if allow-from is applied and the browser does not support it, then you have NO clickjacking defense in place.

Remediation

The X-Frame-Options header is easy to change. It only requires a slight web server configuration modification. For more information about implementation visit MDN.

Clone this wiki locally