Route returns sensitive PII without setting Cache-Control HTTP header
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Description
This publicly exposed API endpoint returns non-sensitive personally identifiable information (PII) without implementing the Cache-Control header. This header instructs browsers how to cache HTTP responses. Without this header, sensitive API responses might be cached inappropriately, potentially exposing confidential information to unintended users through shared browsers.
Sensitive PII is information that, if inadvertently disclosed, could have significant consequences for the data subject.
Sensitive PII data can encompass a wide range of information, including:
- Health information, which includes medical records or insurance information.
- Government information, which includes social security information or other government related data.
- Proprietary information, which includes secrets or intellectual property (IP).
Note: Datadog is only able to detect certain types of PII.
Implement the Cache-Control header in all API responses. Use the ’no-store’ value to prevent caching of sensitive data.
Example header values: