← Back to Baseline

MB-R150

HUMAN VERIFICATION REQUIRED ASVS 3.4.5 Referrer policy

MB-C15 ASVS Level 2 Human Assurance Medium

The application sets a referrer policy to prevent leakage of technically sensitive data to third-party services via the 'Referer'HTTP request header field. This can be done using the Referrer-Policy HTTP response header field or via HTML element attributes. Sensitive data could include path and query data in the URL, and for internal non-public applications also the hostname.