Uploaded image for project: 'WildFly Core'
  1. WildFly Core
  2. WFCORE-6723

The X-Content-Type-Options header is not included with responses from the HTTP management interface

XMLWordPrintable

      DAST scanning of WildFly has picked up that on the management interface the Anti-MIME-Sniffing header X-Content-Type-Options is not set to 'nosniff'.

      See https://owasp.org/www-project-secure-headers/#x-content-type-options for background information.

            chaowan@redhat.com Chao Wang
            bstansbe@redhat.com Brian Stansberry
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: