Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Strict-Transport-Security header not set on 404 pages #2717

Closed
dsotirho-ucsc opened this issue Feb 4, 2025 · 1 comment
Closed

Strict-Transport-Security header not set on 404 pages #2717

dsotirho-ucsc opened this issue Feb 4, 2025 · 1 comment
Labels
canary Done by the Clever Canary duplicate [process] This issue or pull request already exists orange [process] Done by the Azul team

Comments

@dsotirho-ucsc
Copy link
Contributor

ZAP scan finding
Severity: Low

HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL). HSTS is an IETF standards track protocol and is specified in RFC 6797.

Example:

Solution:

Ensure that your web server, application server, load balancer, etc. is configured to enforce Strict-Transport-Security.

@dsotirho-ucsc dsotirho-ucsc added the orange [process] Done by the Azul team label Feb 4, 2025
@github-actions github-actions bot added the canary Done by the Clever Canary label Feb 4, 2025
@achave11-ucsc
Copy link
Member

Duplicate of https://github.com/DataBiosphere/azul-private/issues/81, which we closed as won't fix.

@achave11-ucsc achave11-ucsc reopened this Feb 5, 2025
@achave11-ucsc achave11-ucsc closed this as not planned Won't fix, can't repro, duplicate, stale Feb 5, 2025
@achave11-ucsc achave11-ucsc added the duplicate [process] This issue or pull request already exists label Feb 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
canary Done by the Clever Canary duplicate [process] This issue or pull request already exists orange [process] Done by the Azul team
Projects
None yet
Development

No branches or pull requests

2 participants