Open
Description
From ZAP v2.1.5.0 scan on 2025-03-03
Finding severity: Medium
The following URLs (of 404 pages) were found to lack a CSP header:
- https://data.humancellatlas.org/favicon-32x32.png
- https://data.humancellatlas.org/index/catalogs
- https://data.humancellatlas.org/metadata/dictionary/biomaterial/cell_line
- https://data.humancellatlas.org/metadata/dictionary/file/analysis_file
- https://data.humancellatlas.org/metadata/dictionary/file/sequence_file
- https://data.humancellatlas.org/metadata/dictionary/process/analysis_process
- https://data.humancellatlas.org/metadata/dictionary/project/project
- https://data.humancellatlas.org/metadata/dictionary/protocol/aggregate_generation_protocol
- https://data.humancellatlas.org/metadata/dictionary/protocol/sequencing_protocol
- https://data.humancellatlas.org/robots.txt
Recommended Solution:
- Add a CSP header to all 404 pages
- Additionally, if any of the URLs above exist as links on the Portal, replace/remove the link.