GSA / 889-tool

Web service for determining 889 compliance of vendors
1 stars 0 forks source link

HTTP Strict Transport Security (HSTS) Errors and Warnings #155

Open JennaySDavis opened 6 months ago

JennaySDavis commented 6 months ago

Issue Level: Moderate First Discovered: 11/14/2023 Remediation Date: 2/12/2024

felder101 commented 5 months ago

Reviewed the scan report from December and the URL tested is invalid. See screen print below. This is not a correct API url for the 889 Tool.

Image

JennaySDavis commented 1 week ago

During a security meeting on June 9, 2024, it was confirmed that the URLs flagged were already loaded. (https://hstspreload.org/) Dan did an additional verification after the meeting and confirmed. Dan created a GSA generic request ticket for this false positive.

This issue has been resolved and is no longer listed on the June Vulnerability Scan.