Mozilla Foundation Security Advisory 2013-58
X-Frame-Options ignored when using server push with multi-part responses
- Announced
- June 25, 2013
- Reporter
- Frédéric Buclin
- Impact
- Moderate
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 22
- SeaMonkey 2.19
Description
Bugzilla developer Frédéric Buclin reported
that the X-Frame-Options
header is ignored when server push is used
in multi-part responses. This can lead to potential clickjacking on sites that
use X-Frame-Options
as a protection.