Uploaded image for project: 'Ibexa IBX'
  1. Ibexa IBX
  2. IBX-2921

Disable TRACE/TRACK

Details

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Medium Medium
    • None
    • 2.5.29, 3.3.19, 4.0.6, 4.1.3
    • None
    • Varnish, Fastly

    Description

      To avoid Cross Site Tracing (XST) we should probably disable TRACE/TRACK by default. This affects Apache, Nginx, and possibly Varnish.

      See https://owasp.org/www-community/attacks/Cross_Site_Tracing
      and https://deadliestwebattacks.com/appsec/2010/05/18/cross-site-tracing-xst-the-misunderstood-vulnerability.html

      I have reduced the priority because 1) the issue is 19 years old, and 2) modern browsers block this method, for a long time now.

      Remediations:

      Designs

        Attachments

          Activity

            People

              Unassigned Unassigned
              gunnstein.lye@ibexa.co Gunnstein Lye
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated: