Home / Vulnerability Database / Go : Missing HSTS header
Go

Go : Missing HSTS header

Classification

OWASP Top 10 2017
OWASP Top 10 2021
PCI DSS 4.0

Overview

HTTP Strict Transport Security (HSTS) is an opt-in security enhancement that is specified by a web application through the use of a special response header.

If the application uses http requests and the HSTS header is missed, man in the middle attack is possible .

MEDIUM

DerScanner Severity Score

Do you want to fix Go : Missing HSTS header in your application?

See also

Go

Go : Undocumented feature: special account

Go

Go : Nil salt

Go

Go : Logging into system output