You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
AppScan DAST scan should show secure "X-Content-Type-Options" header
Actual behaviour
AppScan DAST scan shows Missing or insecure "X-Content-Type-Options" header
Steps to reproduce the behavior
AppScan DAST scans for Stratos URL https://ui.169.53.186.50.nip.io. AppScan detected that the "X-Content-Type-Options" response header is missing or has an insecure value, which increases exposure to drive-by download attacks
Log output covering before error and any error statements
Stratos Version
4.4.0
Frontend Deployment type
Backend (Jet Stream) Deployment type
Expected behaviour
AppScan DAST scan should show secure "X-Content-Type-Options" header
Actual behaviour
AppScan DAST scan shows Missing or insecure "X-Content-Type-Options" header
Steps to reproduce the behavior
AppScan DAST scans for Stratos URL https://ui.169.53.186.50.nip.io. AppScan detected that the "X-Content-Type-Options" response header is missing or has an insecure value, which increases exposure to drive-by download attacks
Log output covering before error and any error statements
Detailed Description
Enforce the use of HTTPS when sending sensitive information
Context
Possible Implementation
Config your server to use the "X-Content-Type-Options" header with "nosniff" value
The text was updated successfully, but these errors were encountered: