pcs WebUI missing cache-control headers
Issue
- A security scan of RHEL showed that sensitive data may remain in browser after user leaves site due to missing Cache-Control headers on the pacemaker WebUI port (2224) used by
pcsd
.
Environment
- Red Hat Enterprise Linux 6, 7, 8, 9 with High Availability or Resilient Storage Add-on
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.