Hello,
We have identified the following vulnerability on our Proxmox VE web interface:
HSTS Missing From HTTPS Server (RFC 6797)
Is there an officially supported way to configure the Strict-Transport-Security (HSTS) HTTP header directly in pveproxy?
We could not find a documented native configuration option for this.
If there is no supported way to configure it, is using a reverse proxy the recommended approach?
Also, if we manually modify pveproxy or its underlying configuration to add the HSTS header, would this be considered a supported configuration and would the changes be preserved after updates?
We need this information to address the finding and provide evidence to our Compliance team.
Thank you!
We have identified the following vulnerability on our Proxmox VE web interface:
HSTS Missing From HTTPS Server (RFC 6797)
Is there an officially supported way to configure the Strict-Transport-Security (HSTS) HTTP header directly in pveproxy?
We could not find a documented native configuration option for this.
If there is no supported way to configure it, is using a reverse proxy the recommended approach?
Also, if we manually modify pveproxy or its underlying configuration to add the HSTS header, would this be considered a supported configuration and would the changes be preserved after updates?
We need this information to address the finding and provide evidence to our Compliance team.
Thank you!