cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Vulnerability - HSTS header does not contain includeSubDomains

L3 Networker

This vulnerability is detected on global protect public ip.

 

HSTS header does not contain includeSubDomains

The HTTP Strict Transport Security (HSTS) header does not contain the includeSubDomains directive. This directive instructs the browser to also enforce the HSTS policy over subdomains of this domain.
Expected Headers > strict-transport-security: max-age=[anything]; includeSubDomains; ...
Actual max-age=31536000;

 

Panos version installled 9.1.7.

 

anyone aware about this vulnerability and resolution ?

Who Me Too'd this topic