Cross-site Referrer Leakage through usage of no-referrer-when-downgrade in Referrer-Policy

Severity: Information
Summary#

Invicti detected that no-referrer-when-downgrade is used in the Referrer-Policy declaration.

Impact#

Referrer leakage is possible between two sites if they use either same or a higher protocol.

Remediation#

See all available options and make sure that the current option really suits your need.

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works