HSTS Missing from HTTPS Server (RFC 6797) on RHOCP node - Port 9637 in RHOCP 4.
Issue
-
HSTS (HTTP Strict Transport Security) is not being enforced on HTTPS servers running on RHOCP node.
-
The issue occurs on port 9637 in addition to port 10250.
-
Nessus reports vulnerability for OCP nodes on port 9637 in addition to port 10250. HSTS Missing From HTTPS Server (RFC 6797)
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.