Project

General

Profile

Actions

Bug #22248

closed

Add includeSubdomains to HSTS header

Added by Alexis Mousset almost 2 years ago. Updated almost 2 years ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
No

Description

The absence of this option allows more downgrade attacks, espacially on cookies which are sen ton subdomains (as explained in the owasp cheatsheet).

It carries an additionnal operational risk though, as it can easily impact other sites/applications hosted on a current or future subdomain of the Rudder domain.

We need to document this clearly in the settings.


Subtasks 1 (0 open1 closed)

Bug #22274: Add includeSubdomains to HSTS header with correct property nameReleasedFrançois ARMANDActions
Actions

Also available in: Atom PDF