πΌ [ELB.4] Application Load Balancer should be configured to drop invalid http headers
-
Contextual name: πΌ [ELB.4] Application Load Balancer should be configured to drop invalid http headers
-
ID:
/frameworks/aws-fsbp-v1.0.0/elb/04
-
Located in: πΌ Elastic Load Balancing (ELB)
Descriptionβ
By default, Application Load Balancers are not configured to drop invalid HTTP header values. Removing these header values prevents HTTP desync attacks.
Similarβ
- AWS Security Hub
- Internal
- ID:
dec-c-2a4d3f5a
- ID:
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|