
A product is releasing tonight.
Security found:
A. Missing CSP, with no confirmed injection
B. Login rate limiting only by IP
C. Server version disclosed in headers
D. Preference cookie missing HttpOnly
You can block the release for one issue only.
Which one do you choose, and what evidence would change your answer?
English

