Actions
Feature #24583
closedRemove HTTP Referer
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Fixed
Description
We are currently running Redmine 2.4.3.stable.12909 on Ubuntu
if we have an external URL in our Intranet Redmine, the external website can track the Intranet origin which poses a security concern.
Please let us know on how to fix this?
Related issues
       Updated by Toshi MARUYAMA almost 9 years ago
      Updated by Toshi MARUYAMA almost 9 years ago
      
    
    - Tracker changed from Defect to Feature
       Updated by Go MAEDA about 7 years ago
      Updated by Go MAEDA about 7 years ago
      
    
    - Related to Feature #29660: Add Referrer-Policy header to prevent browsers from sending private data to external sites added
       Updated by Go MAEDA almost 7 years ago
      Updated by Go MAEDA almost 7 years ago
      
    
    - Status changed from New to Closed
- Priority changed from High to Normal
- Resolution set to Fixed
We can close this issue because Redmine 4.0.0 does not send the Referer to external sites. See #29660#note-13 for details.
Actions