Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Zap Findings #585

Open
msaperst opened this issue Oct 29, 2022 · 0 comments
Open

Fix Zap Findings #585

msaperst opened this issue Oct 29, 2022 · 0 comments
Labels

Comments

@msaperst
Copy link
Owner

WARN-NEW: Missing Anti-clickjacking Header [10020] x 3
http://localhost:70 (200 OK)
http://localhost:70/ (200 OK)
http://localhost:70/sitemap.xml (200 OK)
WARN-NEW: X-Content-Type-Options Header Missing [10021] x 9
http://localhost:70/robots.txt (200 OK)
http://localhost:70 (200 OK)
http://localhost:70/ (200 OK)
http://localhost:70/sitemap.xml (200 OK)
http://localhost:70/manifest.json (200 OK)
WARN-NEW: Server Leaks Version Information via "Server" HTTP Response Header Field [10036] x 9
http://localhost:70/robots.txt (200 OK)
http://localhost:70/ (200 OK)
http://localhost:70 (200 OK)
http://localhost:70/sitemap.xml (200 OK)
http://localhost:70/manifest.json (200 OK)
WARN-NEW: Content Security Policy (CSP) Header Not Set [10038] x 3
http://localhost:70/ (200 OK)
http://localhost:70 (200 OK)
http://localhost:70/sitemap.xml (200 OK)
WARN-NEW: Permissions Policy Header Not Set [10063] x 4
http://localhost:70 (200 OK)
http://localhost:70/ (200 OK)
http://localhost:70/sitemap.xml (200 OK)
http://localhost:70/static/js/main.ceda9456.js (200 OK)
WARN-NEW: Timestamp Disclosure - Unix [10096] x 1
http://localhost:70/static/js/main.ceda9456.js (200 OK)
WARN-NEW: HTTP Only Site [10106] x 1
http://localhost:70 (0)
WARN-NEW: Cloud Metadata Potentially Exposed [90034] x 1
http://localhost:70/latest/meta-data/ (200 OK)
WARN-NEW: Missing Anti-clickjacking Header [10020] x 1
http://localhost:70 (200 OK)
WARN-NEW: X-Content-Type-Options Header Missing [10021] x 8
http://localhost:70 (200 OK)
http://localhost:70/favicon.ico (200 OK)
http://localhost:70/logo192.png (200 OK)
http://localhost:70/manifest.json (200 OK)
http://localhost:70/robots.txt (200 OK)
WARN-NEW: Information Disclosure - Suspicious Comments [10027] x 1
http://localhost:70/static/js/main.ceda9456.js (200 OK)
WARN-NEW: Server Leaks Version Information via "Server" HTTP Response Header Field [10036] x 8
http://localhost:70 (200 OK)
http://localhost:70/favicon.ico (200 OK)
http://localhost:70/logo192.png (200 OK)
http://localhost:70/manifest.json (200 OK)
http://localhost:70/robots.txt (200 OK)
WARN-NEW: Content Security Policy (CSP) Header Not Set [10038] x 2
http://localhost:70 (200 OK)
http://localhost:70/sitemap.xml (200 OK)
WARN-NEW: Storable and Cacheable Content [10049] x 8
http://localhost:70 (200 OK)
http://localhost:70/favicon.ico (200 OK)
http://localhost:70/logo1[92](https://github.com/msaperst/snnap/actions/runs/3347938575/jobs/5546462749#step:6:93).png (200 OK)
http://localhost:70/manifest.json (200 OK)
http://localhost:70/robots.txt (200 OK)
WARN-NEW: Permissions Policy Header Not Set [10063] x 3
http://localhost:70 (200 OK)
http://localhost:70/sitemap.xml (200 OK)
http://localhost:70/static/js/main.ceda[94](https://github.com/msaperst/snnap/actions/runs/3347938575/jobs/5546462749#step:6:95)56.js (200 OK)
WARN-NEW: Timestamp Disclosure - Unix [10096] x 1
http://localhost:70/static/js/main.ceda9456.js (200 OK)
WARN-NEW: Modern Web Application [10109] x 3
http://localhost:70 (200 OK)
http://localhost:70/sitemap.xml (200 OK)
http://localhost:70/static/js/main.ceda9456.js (200 OK)

@msaperst msaperst added the MVP label Oct 29, 2022
@msaperst msaperst linked a pull request Oct 29, 2022 that will close this issue
Merged
@msaperst msaperst mentioned this issue Oct 29, 2022
Merged
@msaperst msaperst removed a link to a pull request Oct 29, 2022
Merged
@msaperst msaperst mentioned this issue Dec 12, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant