Description
Acunetix evaluated the scan target's Content Security Policies, checked for misconfigurations and potentially unintended side-effects of otherwise valid configurations, and offers the following suggestions on how to change existing policies for improved security and maximum compatibility.
Remediation
See alert details for available remediation advice.
References
Using Content Security Policy (CSP) to Secure Web Applications
Related Vulnerabilities
Internet Information Server returns IP address in HTTP header (Content-Location)
XML external entity injection via File Upload
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Content-Security-Policy-Report-Only Cannot Be Declared Without report-uri Directive
Weak Nonce Detected in Content Security Policy (CSP) Declaration