Impact of setting glide.security.header.auto_set_x_content_type_options property
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-15-2023 07:49 AM
Hey all,
I have been looking into some of the Instance Hardening properties and came across the recommendation to set the glide.security.header.auto_set_x_content_type_options to true. As I understand setting this to TRUE will help mitigate the risk of MIME Confusion attacks by requiring the Content Type to be specified in the HTTPS Respone.
I am trying to understand the impact of enabling this in an environment where there are existing integrations inbound and outbound, both SOAP and REST. What are your experiences in enabling this property and are there any big risks or foreseen impacts that come to mind?
Thanks,
Ethan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2023 04:19 PM
@Ethan Davies very curious if you got an answer to this question anywhere else? My team is also looking into this setting due to a recommendation from a security tool.
Thanks, Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2024 08:28 AM
@Ethan Davies and @J McMillan Did either of you receive any feedback on this. Seeking to understand the impact. thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2024 06:11 AM
I did not - we did not end up changing the property in the end. It is something you can probably raise a NowSupport ticket for though, I am sure they will give you an answer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2024 11:25 AM
Thanks so much!