Wir nutzen Cookies, um Ihnen eine optimale Nutzung dieser Webseite zu ermöglichen. Mehr Informationen finden Sie im Datenschutzhinweis. Wir nehmen an, dass Sie damit einverstanden sind, falls Sie diese Webseite weiter besuchen.

Ihre Cookie-Einstellungen
Ihre Einstellungen wurden aktualisiert.
Damit die Änderungen wirksam werden, löschen Sie bitte Ihre Browser-Cookies und den Cache und laden dann die Seite neu.

Werk #6774: Add Content-Security-Policy header to prevent some cross site scripting and injection attacks

KomponenteGUI
TitelAdd Content-Security-Policy header to prevent some cross site scripting and injection attacks
Datum2018-09-28 09:41:53
Checkmk EditionCheckmk Raw Edition (CRE)
Checkmk Version1.6.0b1
LevelTrivial Change
KlasseSecurity Fix
KompatibilitätKompatibel - benötigt kein manuelles Eingreifen

When requesting pages from the GUI a Content-Security-Policy is now been set in the HTTP response. Using this mechanism the application can tell the browser which things are allowed to be done by the web page in the context of the browser.

We are now, for example limiting the URLs where AJAX calls can be made to or the URLs which can be used as form targets. This helps to prevent some XSS and other injection attacks.

The configuration of this policy is made in the apache configuration file etc/apache/conf.d/security.conf. In case you want to have a look at the details or want to extend the policy somehow you may edit the file in the context of your site configuration. To apply the changes you need to restart your site apache using omd restart apache.

In case of trouble please let us know. We can probably adapt the default configuration to solve common issues with this policy for all users.

One thing that may affect users that include Check_MK pages on other web pages using frames or iframes: We set the frame-ancestors option to 'self' which means that only pages with the same protocol, url and port as the Check_MK page may refer to Check_MK pages. You can extend this statement with the URLs you want to allow.