- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.
07-18-2021 06:18 PM - edited 07-18-2021 06:56 PM
This vulnerability is detected on global protect public ip.
HSTS header does not contain includeSubDomains
The HTTP Strict Transport Security (HSTS) header does not contain the includeSubDomains directive. This directive instructs the browser to also enforce the HSTS policy over subdomains of this domain.
Expected Headers > strict-transport-security: max-age=[anything]; includeSubDomains; ...
Actual max-age=31536000;
Panos version installled 9.1.7.
anyone aware about this vulnerability and resolution ?