laptop and a wrench

漏洞

The HTTP Strict Transport Security (HSTS) header is not present on 302 (redirect) responses for Portal for ArcGIS.

Portal for ArcGIS
漏洞 ID 编号 BUG-000158917
已提交June 7, 2023
上次修改时间December 11, 2024
适用范围Portal for ArcGIS
找到的版本10.9.1
操作系统Windows Server
操作系统版本2016 64 Bit
修正版本11.2
状态Fixed

解决办法

There is not currently a workaround to fix this. However, the HSTS header is present on the internal Portal for ArcGIS site if HSTS is configured in the settings. There is only an issue when security scanners run the scan on https://fqdn:7443, and it presumes HSTS is not enabled. This is because the URL redirects to Portal for ArcGIS Home, and the redirect itself does not have the HSTS header present.

重现步骤

漏洞 ID: BUG-000158917

软件:

  • Portal for ArcGIS

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项