issues
search
Facetorushikesh
/
issue_demo
0
stars
0
forks
source link
Fix DAST Issue : CSP: Wildcard Directive
#103
Closed
Facetorushikesh
closed
6 months ago
Facetorushikesh
commented
6 months ago
Scan Date
: Wed, 1 May 2024 01:44:12
URLs Impacted
:
https://tuesday-roja-vm-9591.fyre.ibm.com:12443
https://tuesday-roja-vm-9591.fyre.ibm.com:12443/
DAST Scan Results
CWE ID
Severity
Description
Location
Evidence
Solution
693
Medium
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Method:
GET
Parameter:
Content-Security-Policy
default-src 'self'; font-src 'self'; img-src 'self' data:; frame-ancestors 'none'; object-src 'none'; script-src 'self'; connect-src 'self'; style-src 'self' 'unsafe-inline';
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Scan Date: Wed, 1 May 2024 01:44:12 URLs Impacted:
DAST Scan Results
Parameter: Content-Security-Policy