漏洞描述
This check detects if there are any passive content being loaded over HTTP instead of HTTPS.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
developer.mozilla.orghttps://developer.mozilla.org/en-US/docs/Web/Security/Mixed_content↗portswigger.nethttps://portswigger.net/kb/issues/01000400_mixed-content↗resources.infosecinstitute.comhttps://resources.infosecinstitute.com/topics/vulnerabilities/https-mixed-content-vulnerability/↗docs.gitlab.comhttps://docs.gitlab.com/ee/user/application_security/dast/checks/319.1.html↗