Skip to content
This repository has been archived by the owner on Nov 21, 2024. It is now read-only.

Commit

Permalink
Update penetration-test-report.md
Browse files Browse the repository at this point in the history
  • Loading branch information
EngincanV committed Jul 4, 2024
1 parent 9495548 commit dbb5563
Showing 1 changed file with 0 additions and 2 deletions.
2 changes: 0 additions & 2 deletions en/others/penetration-test-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -302,8 +302,6 @@ Manually confirm that the timestamp data is not sensitive, and that the data can

This vulnerability was reported as a positive alert, because ABP uses the [zxcvbn](https://github.com/dropbox/zxcvbn) library for [password complexity indicators](https://docs.abp.io/en/commercial/latest/ui/angular/password-complexity-indicator-component). This library is one of the most used password strength estimator and it does not disclosure any sensitive data related to web server's timestamp and therefore it's a **false-positive** alert.

---

### X-Content-Type-Options Header Missing [Risk: Low] - Positive (Fixed)

- *[GET]https://localhost:44349/client-proxies/account-proxy.js?_v=638550091940000000 (and other client-proxies related URLs)*
Expand Down

0 comments on commit dbb5563

Please sign in to comment.