Summary
Acunetix 360 detected that no-referrer-when-downgrade
is used in the Referrer-Policy declaration.
If a comma-separated referrer-policy is specified in the header, fallback policy is used only if the browser does not support the set referrer-policy, which may cause Cross-site Referrer Leakage.
Impact
Referrer leakage is possible between two sites if they use either same or a higher protocol.
Remediation
See all available options and make sure that the current option really suits your need.