Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Codfront Labs Subscribe
Filtered by product Http Strict Transport Security
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5505 1 Codfront Labs 1 Http Strict Transport Security 2017-07-25 6.8 MEDIUM N/A
The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.