Insecure or unset HTTP headers - Content-Security-Policy
Description
The application has unnsafe configurations regarding the Content-Security-Policy header. This may be because:
- Header is missing from server responses.
- The header has not defined mandatory security policies.
- Defined security policies contain insecure values.
Impact
- Embed content, scripts, blobs or images from potentially malicious sources.
- Make possible to carry attacks like Cross-Site Scripting, Cross-Site Leaks, among others.
Recommendation
Set the Content-Security-Policy header in the server responses and configure it in a secure way.
Threat
Unauthorized attacker from Internet.
Expected Remediation Time
⌚ 15 minutes.
Score
Default score using CVSS 3.1. It may change depending on the context of the src.
Base
- Attack vector: N
- Attack complexity: H
- Privileges required: N
- User interaction: R
- Scope: U
- Confidentiality: L
- Integrity: L
- Availability: N
Temporal
- Exploit code maturity: P
- Remediation level: O
- Report confidence: C
Result
- Vector string: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
- Score:
- Base: 4.2
- Temporal: 3.8
- Severity:
- Base: Medium
- Temporal: Low
Score 4.0
Default score using CVSS 4.0 . It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: H
- Attack Requirements: N
- Privileges required: N
- User interaction: P
- Confidentiality (VC): L
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: P
Result 4.0
- Vector string: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
- Score:
- CVSS-BT: 1.3
- Severity:
- CVSS-BT: Low
Requirements
- 062.Define standard configurations
- 117.Do not interpret HTML code
- 175.Protect pages from clickjacking
- 349.Include HTTP security headers
Fixes
free trial
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.