You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We performed a security check on the admin interface of Carapace and we noticed a vulnerability caused by the presence of the http TRACE method.
It would be advisable to disable it.
Check info:
THREAT:
The remote Web server supports the TRACE and/or TRACK HTTP methods, which makes it easier for remote attackers to steal cookies and
authentication credentials or bypass the HttpOnly protection mechanism.
Track / Trace are required to be disabled to be PCI compliance.
IMPACT:
If this vulnerability is successfully exploited, attackers can potentially steal cookies and authentication credentials, or bypass the HttpOnly
protection mechanism.
SOLUTION:
Disable these methods in your web server's configuration file.
The text was updated successfully, but these errors were encountered:
We performed a security check on the admin interface of Carapace and we noticed a vulnerability caused by the presence of the http TRACE method.
It would be advisable to disable it.
Check info:
The text was updated successfully, but these errors were encountered: