HTTP Strict Transport Security (HSTS) Header Missing in vCenter 8.x
search cancel

HTTP Strict Transport Security (HSTS) Header Missing in vCenter 8.x

book

Article ID: 452386

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

This article addresses customer inquiries regarding missing HTTP Strict Transport Security (HSTS) headers on specific URLs in vCenter Server.

 

A security scan may detect a missing HSTS header on certain URLs on port 443 within vCenter. This header is intended to inform the browser to cache the fact that a URL is HTTPS-only, ensuring the browser always enforces HTTPS for that connection.

Environment

vCenter 8.x

vCenter 9.x

Cause

Engineering has confirmed that the HSTS header is missing on the identified URLs. This behavior did not meet the severity criteria required for a fix in 8.x patch releases.

Resolution

The fix for the missing HSTS header has been implemented in VCF 9.0. Customers concerned about this finding should plan an upgrade to VCF 9.0.x for the resolution.

Note: As this header primarily protects against man-in-the-middle (MitM) attacks by enforcing HTTPS after an initial connection, the risk is significantly reduced in dark site environments where such attacks are unlikely or not possible.

Additional Information

Vulnerability scan detecting HSTS Missing From HTTPS Server - https://knowledge.broadcom.com/external/article?articleNumber=323223