Skip to content

Helmet Security Response Header Disabled

Description

One or more Security Response headers are explicitly disabled in Helmet, which can make the application more vulnerable to attacks.

Examples

Insecure Code

javascript
const helmet = require('helmet'); app.use(helmet({ frameguard: false }));

Secure Code

javascript
const helmet = require('helmet'); app.use(helmet({ frameguard: true }));

Remediation

Enable the disabled Security Response headers in Helmet by setting their corresponding options to true.

Rule Details

FieldValue
IDCODE-0400
CategoryWeb
SeverityMEDIUM
CWECWE-358
ConfidenceHIGH
ImpactMEDIUM
LikelihoodMEDIUM
ExploitabilityMODERATE
TagsSecurity Response Header, Helmet
OWASPA6:2017-Security Misconfiguration, A05:2021-Security Misconfiguration