Missing Critical Security Headers in OpenBlow
OpenBlow whistleblowing软件缺少关键HTTP安全头(如CSP、Referrer-Policy等),导致XSS、点击劫持等风险。CVSS评分8.2(高危)。
You must login to view this content
This week's update is the last remote one for a while as we wind up more than a month of travel. I'm pushing this out just before we jump on the Qantas plane home... right after they've advised just how much of my data