<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.kde.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugs.kde.org/"
          
          maintainer="sysadmin@kde.org"
>

    <bug>
          <bug_id>259070</bug_id>
          
          <creation_ts>2010-12-07 02:50:20 +0000</creation_ts>
          <short_desc>Konqueror should support X-FRAME-OPTIONS header to protect against clickjacking</short_desc>
          <delta_ts>2022-11-17 05:12:57 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>2</classification_id>
          <classification>Applications</classification>
          <product>konqueror</product>
          <component>khtml</component>
          <version>4.5.2</version>
          <rep_platform>Gentoo Packages</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WORKSFORME</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>NOR</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>0</everconfirmed>
          <reporter>hanno</reporter>
          <assigned_to name="Konqueror Bugs">konqueror-bugs-null</assigned_to>
          <cc>aj</cc>
    
    <cc>rdieter</cc>
    
    <cc>than</cc>
    
    <cc>tim</cc>
          
          <cf_commitlink></cf_commitlink>
          <cf_versionfixedin></cf_versionfixedin>
          <cf_sentryurl></cf_sentryurl>
          <votes>0</votes>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1054639</commentid>
    <comment_count>0</comment_count>
    <who name="">hanno</who>
    <bug_when>2010-12-07 02:50:20 +0000</bug_when>
    <thetext>Version:           4.5.2 (using KDE 4.5.4) 
OS:                Linux

Clickjacking is a way to use invisible iframes and javascript to force users to click on actions on web applications. It&apos;s similar to CSRF.

Most other browsers now support a header X-FRAME-OPTIONS, which can be set to &quot;DENY&quot; or &quot;SAMEORIGIN&quot; so web applications can avoid being displayed within iframes. konqueror does not support that yet and leaves users vulnerable to clickjacking.

Reproducible: Always

Steps to Reproduce:
See http://int21.de/frametest/

Actual Results:  
You see red iframes.

Expected Results:  
Red iframes should not be displayed.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1262292</commentid>
    <comment_count>1</comment_count>
    <who name="Frédéric Buclin">LpSolit</who>
    <bug_when>2012-06-04 18:47:14 +0000</bug_when>
    <thetext>This is definitely a security issue and all major browsers support it, see the &quot;Browser compatibility&quot; section at:
https://developer.mozilla.org/en/The_X-FRAME-OPTIONS_response_header

For instance, Bugzilla uses it to protect sensitive bugs and attachments. All Konqueror users are exposed to clickjacking attacks.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1394638</commentid>
    <comment_count>2</comment_count>
    <who name="tim">tim</who>
    <bug_when>2013-09-02 22:48:06 +0000</bug_when>
    <thetext>I think and hope the problem is solved after two years. In my Installation Konqueror passed frametest http://int21.de/frametest/ listet in the first comment. But i can&apos;t say if the test actually works correctly.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1394744</commentid>
    <comment_count>3</comment_count>
    <who name="">hanno</who>
    <bug_when>2013-09-03 11:56:08 +0000</bug_when>
    <thetext>Just had some private E-Mail exchange with Tim. The issue is fixed if Konqueror is used with Webkit, but it is not fixed with KHTML (which is still the default).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1433857</commentid>
    <comment_count>4</comment_count>
    <who name="Rex Dieter">rdieter</who>
    <bug_when>2014-03-04 22:12:51 +0000</bug_when>
    <thetext>Re: comment #3

With recent kwebkitpart installs, it takes default priority over khtml (if installed).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1433922</commentid>
    <comment_count>5</comment_count>
    <who name="Than Ngo">than</who>
    <bug_when>2014-03-05 13:06:11 +0000</bug_when>
    <thetext>Hanno, i saw your CVE request on oss-sec, http://seclists.org/oss-sec/2014/q1/476</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2162429</commentid>
    <comment_count>6</comment_count>
    <who name="Justin Zobel">justin.zobel</who>
    <bug_when>2022-10-17 22:53:35 +0000</bug_when>
    <thetext>Thank you for reporting this bug in KDE software. As it has been a while since this issue was reported, can we please ask you to see if you can reproduce the issue with a recent software version?

If you can reproduce the issue, please change the status to &quot;CONFIRMED&quot; when replying. Thank you!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2162564</commentid>
    <comment_count>7</comment_count>
    <who name="">hanno</who>
    <bug_when>2022-10-18 07:16:18 +0000</bug_when>
    <thetext>It seems konqueror now implements x-frame-options. I guess this change happened with the switch to qtwebengine.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2167813</commentid>
    <comment_count>8</comment_count>
    <who name="Bug Janitor Service">bug-janitor</who>
    <bug_when>2022-11-02 05:05:37 +0000</bug_when>
    <thetext>Dear Bug Submitter,

This bug has been in NEEDSINFO status with no change for at least
15 days. Please provide the requested information as soon as
possible and set the bug status as REPORTED. Due to regular bug
tracker maintenance, if the bug is still in NEEDSINFO status with
no change in 30 days the bug will be closed as RESOLVED &gt; WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

If you have already provided the requested information, please
mark the bug as REPORTED so that the KDE team knows that the bug is
ready to be confirmed.

Thank you for helping us make KDE software even better for everyone!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2174263</commentid>
    <comment_count>9</comment_count>
    <who name="Bug Janitor Service">bug-janitor</who>
    <bug_when>2022-11-17 05:12:57 +0000</bug_when>
    <thetext>This bug has been in NEEDSINFO status with no change for at least
30 days. The bug is now closed as RESOLVED &gt; WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

Thank you for helping us make KDE software even better for everyone!</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>