GSA / smartpay-website

SmartPay website
https://federalist-ab31a10d-375d-4040-9324-1ae94e8a36b9.sites.pages.cloud.gov/site/gsa/smartpay-website/
3 stars 0 forks source link

HTTP Strict Transport Security (HSTS) Policy Not Enabled #393

Open JennaySDavis opened 11 months ago

JennaySDavis commented 11 months ago

Issue Level: Moderate First Discovered: 1/22/2022 Remediation Date: 4/22/2022

JennaySDavis commented 10 months ago

The following WebApp Scan finding was from the decommissioned SPCS; this finding is not valid with the new SPCS.

JennaySDavis commented 8 months ago

We are waiting for Tri and the security team to remove this issue from the POAM before closing the ticket.

JennaySDavis commented 4 months ago

During a security meeting on June 9, 2024, it was confirmed that the URLs flagged were already loaded. (https://hstspreload.org/) Dan did an additional verification after the meeting and confirmed. Dan created a GSA generic request ticket for this false positive.

This issue has been resolved and is no longer listed on the June Vulnerability Scan.