Uploaded image for project: 'WildFly Core'
  1. WildFly Core
  2. WFCORE-6723

The X-Content-Type-Options header is not included with responses from the HTTP management interface

XMLWordPrintable

      DAST scanning of WildFly has picked up that on the management interface the Anti-MIME-Sniffing header X-Content-Type-Options is not set to 'nosniff'.

      See https://owasp.org/www-project-secure-headers/#x-content-type-options for background information.

              chaowan@redhat.com Chao Wang
              bstansbe@redhat.com Brian Stansberry
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: