Cross-site Referrer Leakage through usage of no-referrer-when-downgrade in Referrer-Policy
Summary#
Invicti detected that no-referrer-when-downgrade
is used in the Referrer-Policy declaration.
Impact#
Referrer leakage is possible between two sites if they use either same or a higher protocol.
Remediation#
See all available options and make sure that the current option really suits your need.
Classifications#