GSA / 889-tool

Web service for determining 889 compliance of vendors
1 stars 0 forks source link

HTTP Strict Transport Security (HSTS) Policy Not Enabled #153

Open JennaySDavis opened 6 months ago

JennaySDavis commented 6 months ago

Issue Level: Moderate First Discovered: 1/22/2022 Remediation Date: 4/22/2022

JennaySDavis commented 5 months ago

The following WebApp Scan finding was from the decommissioned SPCS; this finding is not valid with the new SPCS.

JennaySDavis commented 4 months ago

We are waiting on Tri and the security team to remove this issue from the POAM before closing the ticket.

JennaySDavis commented 1 week ago

During a security meeting on June 9, 2024, it was confirmed that the URLs flagged were already loaded. (https://hstspreload.org/) Dan did an additional verification after the meeting and confirmed. Dan created a GSA generic request ticket for this false positive.

This issue has been resolved and is no longer listed on the June Vulnerability Scan.