You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
dsotirho-ucsc opened this issue
Jan 30, 2025
· 1 comment
Labels
-[priority] Mediumbug[type] A defect preventing use of the system as specifiedcanaryDone by the Clever Canarycompliance[subject] Information and software securitygroomedinvicti[subject] Represents one or more Invicti findingsorange[process] Done by the Azul team
The Content Security Policy header contains an unquoted none in the frame-src directive. Without quotes, the none value is interpreted as a domain instead of a keyword.
achave11-ucsc
added
bug
[type] A defect preventing use of the system as specified
compliance
[subject] Information and software security
invicti
[subject] Represents one or more Invicti findings
-
[priority] Medium
labels
Feb 5, 2025
-[priority] Mediumbug[type] A defect preventing use of the system as specifiedcanaryDone by the Clever Canarycompliance[subject] Information and software securitygroomedinvicti[subject] Represents one or more Invicti findingsorange[process] Done by the Azul team
Issue:
The Content Security Policy header contains an unquoted
none
in theframe-src
directive. Without quotes, thenone
value is interpreted as a domain instead of a keyword.Suggested fix:
Replace
frame-src none;
withframe-src 'none';
Reproduction:
The text was updated successfully, but these errors were encountered: