Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
2.0.6, 2.1.10, 2.2.7, 3.0.0-alpha-2
-
Reviewed
Description
In order to further improve HBase exposed service for vulnerability scanners, would be nice to implement additional security headers for the Thrift server when HTTP or HTTPS transport is enabled.
Similarly to REST and Web UIs, related tickets are attached.
Attachments
Issue Links
- is related to
-
HBASE-23303 Add security headers to REST server/info page
- Resolved
-
HBASE-26789 Automatically add default security headers to http/rest if SSL enabled
- Resolved
- links to