Summary #

Invicti detected that no-referrer-when-downgrade is used in the Referrer-Policy declaration.

Impact #

Referrer leakage is possible between two sites if they use either same or a higher protocol.

Remediation #

See all available options and make sure that the current option really suits your need.

Classifications #
CWE-200; ISO27001-A.14.2.5; OWASP PC-C9; OWASP 2013-A6; OWASP 2017-A6

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo