# “Cache Management: Insecure Policy” vulnerability detected after version upgrade

**URL:** <https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [October 9, 2023, 7:26am UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627 "2023-10-09T07:26:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Septianingrum.17](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Post date:** [October 9, 2023, 7:26am UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627/1 "2023-10-09T07:26:40Z")

</div>

After I upgraded the elastic stack to 8.6.0 and carried out a vulnerability scan on Kibana using the microfocus tool, there were vulnerabilities as follows:

 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9fb356ff733042786f2fb0483576793809935ca.png)

I have made changes to the Kibana configuration, namely changing

```auto
server.customResponseHeaders:
  Cache-Control: "no-cache, no-store"

```

but that does not solve the problem, this vulnerability is still detected in the next scan.

Please suggest me any solution to rectify this.

---

<div class="post-metadata">

**Author:** ![thomheymann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomheymann/32/87096_2.png) [@thomheymann](https://discuss.elastic.co/u/thomheymann)\
**Post date:** [October 9, 2023, 12:25pm UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627/2 "2023-10-09T12:25:54Z")

</div>

Hi,

Kibana uses the following `Cache-Control` directives to ensure that content is not cached:

```auto
Cache-Control: private, no-cache, no-store, must-revalidate

```

Static assets like script files (which do not contain any user data) should be cached by the browser for improved performance and use the following directive:

```auto
Cache-Control: must-revalidate

```

I can't verify which directives your scanner is picking up since you haven't posted those details but if that's not what you're getting you might have an upstream proxy or load balancer interfering with the header.

---

<div class="post-metadata">

**Author:** ![thomheymann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomheymann/32/87096_2.png) [@thomheymann](https://discuss.elastic.co/u/thomheymann)\
**Post date:** [October 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627/4 "2023-10-13T09:08:16Z")

</div>

I can see from the report that the scanner has made a request to `https://centrallogs-uat.danamon.co.id/translations/en.json`. This is a static asset (english language bundle) and does not contain any user data. As such this file is safe to cache by browsers and you can safely ignore this warning.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2023, 9:09am UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627/5 "2023-11-10T09:09:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
