Project

General

Profile

Actions

Bug #22248

closed

Add includeSubdomains to HSTS header

Bug #22248: Add includeSubdomains to HSTS header

Added by Alexis Mousset over 3 years ago. Updated about 3 years ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
No

Description

The absence of this option allows more downgrade attacks, espacially on cookies which are sen ton subdomains (as explained in the owasp cheatsheet).

It carries an additionnal operational risk though, as it can easily impact other sites/applications hosted on a current or future subdomain of the Rudder domain.

We need to document this clearly in the settings.


Subtasks 1 (0 open1 closed)

Bug #22274: Add includeSubdomains to HSTS header with correct property nameReleasedFrançois ARMANDActions

Updated by Alexis Mousset over 3 years ago Actions #1

  • Status changed from New to In progress
  • Assignee set to Alexis Mousset

Updated by Alexis Mousset over 3 years ago Actions #2

  • Status changed from In progress to Pending technical review
  • Assignee changed from Alexis Mousset to Nicolas CHARLES
  • Pull Request set to https://github.com/Normation/rudder/pull/4628

Updated by Alexis Mousset over 3 years ago Actions #3

  • Status changed from Pending technical review to Pending release

Updated by Alexis Mousset about 3 years ago Actions #4

  • Subtask #22274 added

Updated by Alexis Mousset about 3 years ago Actions #5

  • Fix check changed from To do to Error - Blocking

Updated by Alexis Mousset about 3 years ago Actions #6

  • Fix check changed from Error - Blocking to Checked

Updated by Vincent MEMBRÉ about 3 years ago Actions #7

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 7.2.4 which was released today.

Actions

Also available in: PDF Atom