Voltar ao catalogoLOW-03
Nginx sem security headers
LowAchado ConfirmadoSegurancaRodada 1
Evidencia
`angular/nginx.conf` — ausencia completa de security headers.
Impacto Tecnico
Frontend vulneravel a clickjacking, MIME sniffing e downgrade attacks.
Impacto de Negocio
Superficie de ataque web ampliada.
Recomendacao
Adicionar headers recomendados pelo OWASP Secure Headers Project.
Arquivos Afetados
angular/nginx.conf
Achados Relacionados
{
"id": "LOW-03",
"title": "Nginx sem security headers",
"severity": "Low",
"type": "achado confirmado",
"category": "security",
"description": "O `nginx.conf` do frontend nao possui headers de seguranca recomendados: `X-Frame-Options`, `X-Content-Type-Options`, `Strict-Transport-Security`, `Content-Security-Policy`.",
"evidence": "`angular/nginx.conf` — ausencia completa de security headers.",
"technicalImpact": "Frontend vulneravel a clickjacking, MIME sniffing e downgrade attacks.",
"businessImpact": "Superficie de ataque web ampliada.",
"recommendation": "Adicionar headers recomendados pelo OWASP Secure Headers Project.",
"files": [
"angular/nginx.conf"
],
"pass": 1,
"relatedFindings": [
"INFRA-16"
]
}
Descricao
O
nginx.confdo frontend nao possui headers de seguranca recomendados:X-Frame-Options,X-Content-Type-Options,Strict-Transport-Security,Content-Security-Policy.