GSA / smartpay-website

SmartPay website
https://federalist-ab31a10d-375d-4040-9324-1ae94e8a36b9.sites.pages.cloud.gov/site/gsa/smartpay-website/
3 stars 0 forks source link

Missing X-Content-type-Options Header #555

Open JennaySDavis opened 5 months ago

JennaySDavis commented 5 months ago

Invicti Enterprise detected a missing X-Content-Type-Options header which means that this website could be at risk of a MIME- sniffing attacks.

felder101 commented 3 months ago

I believe this vulnerability is a false positive based on the documentation provided by cloud.gov. The recommended remedy to add the X-Content-Type-Options header with a value of "nosniff" to inform the browser to trust what the site has sent is the appropriate content-type, and to not attempt "sniffing" the real content-type is being done by cloud.gov. Verified value is set and is set within the response headers

Cloud.gov documentation https://cloud.gov/docs/management/headers/

felder101 commented 3 months ago

Ticket has been entered on 7/16/2024 to remove from future scan reports.

JennaySDavis commented 1 month ago

Ticket has been updated to 'In Progress' status.