How to set the X-XSS-Protection header in JBoss EAP 7
Issue
We recently had a penetration test done of JBoss EAP 7 systems and the issue of XSS protection was raised:
"It was observed that Web Browser XSS Protection is not enabled, or is disabled by the configuration of the 'X-XSS-Protection' HTTP response header on the web server."
The recommendation was: "It is highly recommended that management ensure that the web browser's XSS filter is enabled, by setting the X-XSS-Protection HTTP response header to '1'."
Environment
- Red Hat JBoss Enterprise Application Platform
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.