QID 153010
Date Published: 2023-07-11
QID 153010: Misconfigured Strict-Transport-Security Header
HTTP Strict Transport Security (HSTS) header was found to be misconfigured. The HSTS header instructs browsers that all subsequent connections to the website, for a configurable amount of time, should be performed over a secure (HTTPS) connection only. Additionally, it instructs browsers that users should not be permitted to bypass SSL/TLS certificate errors, in the event of an expired or otherwise untrusted certificate for example.
If the max-age is configured to lower value then it is possible for browser to load the page over HTTP plain text protocol. This will expire HSTS over HTTPs connections and expose users potentially to man-in-the-middle (MITM) attacks, SSL stripping, and passive eavesdropper attacks.
Solution
It is advisable to assign the max age directive value to be greater than 10368000 seconds or set it to 31536000 seconds.
Vendor References
CVEs related to QID 153010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|