<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-525 on ZAP</title>
    <link>/alerttags/cwe-525/</link>
    <description>Recent content in CWE-525 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-525/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cache-Control public/max-age with Set-Cookie</title>
      <link>/docs/alerts/200018/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/200018/</guid>
      <description>&lt;p&gt;Flags potentially risky cacheability for responses that appear user-specific and missing cache partitioning indicators.&lt;/p&gt;&#xA;&lt;p&gt;Generated by OWASP PTK DAST Module&lt;/p&gt;</description>
    </item>
    <item>
      <title>Re-examine Cache-control Directives</title>
      <link>/docs/alerts/10015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10015/</guid>
      <description>&lt;p&gt;The cache-control header has not been set properly or is missing, allowing the browser and proxies to cache content. For static assets like css, js, or image files this might be intended, however, the resources should be reviewed to ensure that no sensitive content will be cached.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-1/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-2/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
