- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-08-2024 07:48 AM
Hi
I run a regular scan on our equipment from a public source and I am seeing the following vuln being flagged against the URL that is used for our Palo devices and I was hoping someone would have an answer as there's not much information out there.
The Analysis refers to:
The host header ; frame_ancestors_missing
Hoping someone can advise
Many thanks
D
04-08-2024 01:36 PM
frame-ancestors are served up in the CSP header and essentially just limit the ability to embed a page to whatever you have specified. Whatever you're using for scanning is properly reporting that this isn't present for GlobalProtect; I'm unaware of any ability to customize this behavior. You can reach out to your SE to get a FR put together to add this functionality however.
04-08-2024 01:36 PM
frame-ancestors are served up in the CSP header and essentially just limit the ability to embed a page to whatever you have specified. Whatever you're using for scanning is properly reporting that this isn't present for GlobalProtect; I'm unaware of any ability to customize this behavior. You can reach out to your SE to get a FR put together to add this functionality however.
04-09-2024 01:22 AM
Thank you for this, I received a response from our support partner early this morning and their response is along the same lines. Do you know of any official Palo documentation that advises as such, I'm unable to find anything that outlines this behaviour - I can go back to the online scanner; SecurityScorecard.io to have this false positive removed.
Many thanks
04-09-2024 06:36 AM
I'm not aware of any official documentation specifically stating that frame-ancestors isn't supported; that's kind of asking for documentation to support the lack of a specific functionality, it isn't extremely common that a vendor will take the time to publish that information.
I also want to be clear here that this isn't really a false-positive detection. Your scanner is properly documenting the lack of a specific functionality that would make things more secure if it was utilized, the product that it's scanning simply doesn't support said functionality.
05-09-2024 01:38 AM - edited 05-20-2024 01:20 AM
Thank you so much for the solution. You made my day. I wasn't expecting that I am gonna find your post. I was actually searching for this https://academized.com/custom-thesis website online because my younger brother needs custom thesis writing help and when I was searching for it online, I found link to your post as well.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!