Skip to content

HTTP StrictTransport-Security header was not found in HTTP API responses #2789

Discussion options

You must be logged in to vote

@udittyagi1994 thanks. You should have privately reported this, what you did here is known as irresponsible disclosure. There is an email address (security at RabbitMQ domain) for that listed on the home page and on the Contact Us page. You also haven't provided any version details.

However, we will not delete this issue because there is nothing to fix. The user can set any value for

that they need.

@udittyagi1994 never ever report vulnerabilities, whether real or noise from automated scanners, publicly.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@michaelklishin
Comment options

Answer selected by michaelklishin
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #2786 on February 03, 2021 12:48.