-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SOC2 - Launchpad Penetration Testing Report #104
Comments
A01 Broken Access Control -
A04 Insecure Design -
A05 Security Misconfiguration -
Note: Nothing is fixed at app side regarding the above vulnerabilities as of now, should be handled by the changes done at OMS side. If needed CSP can be handled at app side using meta tags - e.g. Adding below meta tag in index.html file. |
…ermissions-Policy headers in firebase config in context of soc2 compliance (#104).
Improved: Added X-Frame-Options, CSP, strict-transport-security and Permissions-Policy headers in firebase config in context of soc2 compliance (#104).
What is the motivation for adding/enhancing this feature?
Here is the Report -
20240221_OWASP_Top_10_2021_https_launchpad_hotwax_io_home.pdf
What are the acceptance criteria?
All the critical vulnerabilities should be fixed.
Can you complete this feature request by yourself?
Additional information
The text was updated successfully, but these errors were encountered: