Uploaded image for project: 'Kafka'
  1. Kafka
  2. KAFKA-13240

HTTP TRACE should be disabled in Connect

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • connect

    Description

      Modern browsers mostly disable HTTP TRACE to prevent XST (cross-site tracking) attacks. Because of this usually this type of attack isn't too prevalent these days but since it isn't disabled in Connect it may open up possible ways of attacks (and constantly pops up in security scans ). Therefore we'd like to disable it.

      Attachments

        Issue Links

          Activity

            People

              viktorsomogyi Viktor Somogyi-Vass
              viktorsomogyi Viktor Somogyi-Vass
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated: