This article addresses customer inquiries regarding missing HTTP Strict Transport Security (HSTS) headers on specific URLs in vCenter Server.
A security scan may detect a missing HSTS header on certain URLs on port 443 within vCenter. This header is intended to inform the browser to cache the fact that a URL is HTTPS-only, ensuring the browser always enforces HTTPS for that connection.
vCenter 8.x
vCenter 9.x
Engineering has confirmed that the HSTS header is missing on the identified URLs. This behavior did not meet the severity criteria required for a fix in 8.x patch releases.
The fix for the missing HSTS header has been implemented in VCF 9.0. Customers concerned about this finding should plan an upgrade to VCF 9.0.x for the resolution.
Note: As this header primarily protects against man-in-the-middle (MitM) attacks by enforcing HTTPS after an initial connection, the risk is significantly reduced in dark site environments where such attacks are unlikely or not possible.
Vulnerability scan detecting HSTS Missing From HTTPS Server - https://knowledge.broadcom.com/external/article?articleNumber=323223