Facetorushikesh / issue_demo

0 stars 0 forks source link

Fix DAST Issue : Strict-Transport-Security Multiple Header Entries (Non-compliant with Spec) #202

Closed Facetorushikesh closed 3 months ago

Facetorushikesh commented 4 months ago

Scan Date: Wed, 1 May 2024 01:44:12 URLs Impacted:

DAST Scan Results | CWE ID | Severity | Description | Location | Evidence | Solution | | --- | --- | --- | --- | --- | --- | | [319](https://cwe.mitre.org/data/definitions/319.html) | Low | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | **Method:** GET **Parameter:** | | Ensure that only one component in your stack: code, web server, application server, load balancer, etc. is configured to set or add a HTTP Strict-Transport-Security (HSTS) header. |
Facetorushikesh commented 4 months ago

Scan Date: Wed, 1 May 2024 01:44:12 URLs Impacted:

DAST Scan Results | CWE ID | Severity | Description | Location | Evidence | Solution | | --- | --- | --- | --- | --- | --- | | [319](https://cwe.mitre.org/data/definitions/319.html) | Low | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | **Method:** GET **Parameter:** | | Ensure that only one component in your stack: code, web server, application server, load balancer, etc. is configured to set or add a HTTP Strict-Transport-Security (HSTS) header. |