<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>WSTG-V42-ATHN-06 on ZAP</title>
    <link>/alerttags/wstg-v42-athn-06/</link>
    <description>Recent content in WSTG-V42-ATHN-06 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/wstg-v42-athn-06/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Non-Storable Content</title>
      <link>/docs/alerts/10049-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-1/</guid>
      <description>&lt;p&gt;The response contents are not storable by caching components such as proxy servers. If the response does not contain sensitive, personal or user-specific information, it may benefit from being stored and cached, to improve performance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Re-examine Cache-control Directives</title>
      <link>/docs/alerts/10015/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10015/</guid>
      <description>&lt;p&gt;The cache-control header has not been set properly or is missing, allowing the browser and proxies to cache content. For static assets like css, js, or image files this might be intended, however, the resources should be reviewed to ensure that no sensitive content will be cached.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-1/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Retrieved from Cache</title>
      <link>/docs/alerts/10050-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10050-2/</guid>
      <description>&lt;p&gt;The content was retrieved from a shared cache. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storable and Cacheable Content</title>
      <link>/docs/alerts/10049-3/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-3/</guid>
      <description>&lt;p&gt;The response contents are storable by caching components such as proxy servers, and may be retrieved directly from the cache, rather than from the origin server by the caching servers, in response to similar requests from other users. If the response data is sensitive, personal or user-specific, this may result in sensitive information being leaked. In some cases, this may even result in a user gaining complete control of the session of another user, depending on the configuration of the caching components in use in their environment. This is primarily an issue where &amp;ldquo;shared&amp;rdquo; caching servers such as &amp;ldquo;proxy&amp;rdquo; caches are configured on the local network. This configuration is typically found in corporate or educational environments, for instance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Storable but Non-Cacheable Content</title>
      <link>/docs/alerts/10049-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10049-2/</guid>
      <description>&lt;p&gt;The response contents are storable by caching components such as proxy servers, but will not be retrieved directly from the cache, without validating the request upstream, in response to similar requests from other users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Cache Deception</title>
      <link>/docs/alerts/40039/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/40039/</guid>
      <description>&lt;p&gt;Web cache deception may be possible. It may be possible for unauthorised user to view sensitive data on this page.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
