<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerability - HSTS header does not contain includeSubDomains in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/458422#M1461</link>
    <description>&lt;P&gt;I got this below response from TAC for above vulnerability-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apologies for delayed response.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;We have checked internally and from the information we are not supporting HSTS for subdomain.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;We would reach out to your account team to get the feature in Firewall for GP VPN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;As, we raised voting request with our internal team for your Feature request with FR ID: 6826.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jan 2022 18:16:11 GMT</pubDate>
    <dc:creator>shubhamgupta</dc:creator>
    <dc:date>2022-01-12T18:16:11Z</dc:date>
    <item>
      <title>Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/420234#M1238</link>
      <description>&lt;P&gt;This vulnerability is detected on global protect public ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HSTS header does not contain includeSubDomains&lt;/P&gt;&lt;P&gt;The HTTP Strict Transport Security (HSTS) header does not contain the includeSubDomains directive. This directive instructs the browser to also enforce the HSTS policy over subdomains of this domain.&lt;BR /&gt;Expected Headers &amp;gt; strict-transport-security: max-age=[anything]; includeSubDomains; ...&lt;BR /&gt;Actual max-age=31536000;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Panos version installled 9.1.7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone aware about this vulnerability and resolution ?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 01:56:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/420234#M1238</guid>
      <dc:creator>Deepak25</dc:creator>
      <dc:date>2021-07-19T01:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/442872#M1350</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183271"&gt;@Deepak25&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am also facing the same issue, Did you find any resolution for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 10:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/442872#M1350</guid>
      <dc:creator>shubhamgupta</dc:creator>
      <dc:date>2021-10-22T10:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/443649#M1354</link>
      <description>&lt;P&gt;Currently, it's considered as designed since Strict-Transport-Security is only for the Global Protect server itself and we don't have control for the sub domains.&lt;BR /&gt;We have a feature request (FR 17182) for this. You may want to contact Palo Alto Networks sales department to add more weight.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 01:42:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/443649#M1354</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2021-10-27T01:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/458017#M1459</link>
      <description>&lt;P&gt;Any update on the SubDomains, when it's planned for a release.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 17:36:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/458017#M1459</guid>
      <dc:creator>MALLIKARJUN-SHIGLI</dc:creator>
      <dc:date>2022-01-11T17:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/458422#M1461</link>
      <description>&lt;P&gt;I got this below response from TAC for above vulnerability-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apologies for delayed response.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;We have checked internally and from the information we are not supporting HSTS for subdomain.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;We would reach out to your account team to get the feature in Firewall for GP VPN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;As, we raised voting request with our internal team for your Feature request with FR ID: 6826.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 18:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/458422#M1461</guid>
      <dc:creator>shubhamgupta</dc:creator>
      <dc:date>2022-01-12T18:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/461365#M1469</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Any update on the SubDomains?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 11:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/461365#M1469</guid>
      <dc:creator>Mignone35</dc:creator>
      <dc:date>2022-01-27T11:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/468425#M1515</link>
      <description>&lt;P&gt;I have the same issue too.&lt;/P&gt;&lt;P&gt;And I also want to know does there any update about SubDomins.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 00:21:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/468425#M1515</guid>
      <dc:creator>MingWang</dc:creator>
      <dc:date>2022-02-25T00:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/507384#M1678</link>
      <description>&lt;P&gt;I have the same problem&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 09:45:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/507384#M1678</guid>
      <dc:creator>MBTNA</dc:creator>
      <dc:date>2022-06-30T09:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/508945#M1698</link>
      <description>&lt;P&gt;any update? im the same&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 10:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/508945#M1698</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2022-07-14T10:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/511092#M1723</link>
      <description>&lt;P&gt;seems like everyones been waiting for long on this one, we got a similar customer request.. anyone checked this in v10?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 06:22:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/511092#M1723</guid>
      <dc:creator>AllwynMascarenhas</dc:creator>
      <dc:date>2022-08-05T06:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerability - HSTS header does not contain includeSubDomains</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/536495#M1897</link>
      <description>&lt;P&gt;Paloalto support portal mentioned t&lt;SPAN&gt;he includeSubDomains directive is not relevant to GlobalProtect because it is not a hosted website whereby statically defined.&amp;nbsp;No resolution, it is expected behavior.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001W2ZCAU" target="_blank"&gt;GlobalProtect HTTP header missing includeSubDomains in Strict-T... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 01:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-hsts-header-does-not-contain-includesubdomains/m-p/536495#M1897</guid>
      <dc:creator>ElvisJan</dc:creator>
      <dc:date>2023-03-27T01:34:40Z</dc:date>
    </item>
  </channel>
</rss>

