F-2024-0004·configuration
Strict-Transport-Security not enforced
TL;DR
The site did not return an HSTS header, leaving the browser without protection against protocol downgrade or SSL-stripping attempts.
Severity
INFO
Impact
LOW
Likelihood
LOW
Method
MManual review
CAT.
Complexity
LOW
Exploitability
LOW
02Section · Description
Description
Responses did not include the Strict-Transport-Security header. Without HSTS, browsers do not enforce HTTPS-only access on first visit or after the policy expires, widening the window for SSL-stripping or downgrade attacks.
03Section · Impact
Impact
Informational. Defense-in-depth gap rather than a directly exploitable bug.
04Section · Recommendation
Recommendation
Return Strict-Transport-Security: max-age=63072000; includeSubDomains; preload on all responses.
Hopium: Acknowledged. Zealynx: Acknowledged.