Re: [ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-06 Thread Tomas Jelinek
Hi S Sathish S, New pcs-0.10.16 version containing the fix for this issue has just been released upstream. Regards, Tomas Dne 04. 04. 23 v 19:14 S Sathish S napsal(a): Hi Tomas/Team, In our case PCS WEB UI us disabled while accessing PCS WEB UI URL we are getting 404 response, As you stat

Re: [ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-04 Thread S Sathish S via Users
Hi Tomas/Team, In our case PCS WEB UI us disabled while accessing PCS WEB UI URL we are getting 404 response, As you stated we are getting this vulnerability "HSTS Missing From HTTPS Server" on Tenable scan. While going through changelog we can see fixes are available in unreleased version ca

Re: [ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-04 Thread Tomas Jelinek
Hi S Sathish S, pcs is sending Strict-Transport-Security header since version pcs-0.9.168. There were further fixes in pcs-0.10 branch which you can find in pcs changelog [1]: * in pcs-0.10.5: Added missing Strict-Transport-Security headers to redirects * in pcs-0.10.14: Set 'Strict-Transport-

[ClusterLabs] HSTS Missing From HTTPS Server on pcs daemon

2023-04-03 Thread S Sathish S via Users
Hi Team, In our product we are using pcs-0.10.15 version while running tenable scan found below vulnerability reported on 2224 pcsd daemon. Moreover we have disable PCSD Web UI in our application still vulnerability reported in the system. Plugin ID : 84502 Plugin Name : HSTS Missing From HTTP