Project

General

Profile

Actions

Bug #29206

open

Links from Foreman app to documentation can reveal hostnames

Added by Lukas Zapletal about 4 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

HTTP referer header can possibly reveal some bits of information when Satellite user clicks on documentation or possibly any external link. Possible solutions are HTTP headers to prevent this (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy) or a special page-in-the middle page that resets referer to a harmless URL.

No data to display

Actions

Also available in: Atom PDF