Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-127

CONTENT SECURITY POLICY NOT SPECIFIED

    Details

    • Type: Change Request
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have
    • Sprint:
      ST Sprint 2

      Description

      Vulnerability Description
      The server does not include a Content-Security-Policy header in HTTP(S) responses.

      Impact
      Content Security Policy is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. To use CSP, the developer writes a set of rules to govern which servers an app can open connections to, limit the types of content it can download from those servers, and restrict the use of dangerous features like inline scripts and the eval function.

      Verification and Attack Information
      Praetorian identified this issue through a manual application walkthrough by reviewing HTTP headers. While doing so, Praetorian noted that Content-Security-Policy header was not included in server response headers.

      Recommendation
      Best practices for web applications suggest that servers should specify a Content Security Policy (CSP) to whitelist the actions that their users' browsers are allowed to take.

      References
      https://developer.mozilla.org/en-US/docs/Web/Security/CSP/Introducing_Content_Security_Policy
      http://www.html5rocks.com/en/tutorials/security/content-security-policy/

        Attachments

          Activity

          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          New Request Pending for Approval
          46s 1
          Vijayendra Shinde (Inactive) made transition -
          Pending for Approval Approved for Development
          2s 1
          Vijayendra Shinde (Inactive) made transition -
          Approved for Development In Development
          2s 1
          Zeeshan Chishty (Inactive) made transition -
          In LB Testing Reopen in Local
          4d 7h 36m 1
          Niteen Surwase (Inactive) made transition -
          Reopen in Local In Development
          6d 23h 15m 1
          Niteen Surwase (Inactive) made transition -
          Stage Testing Reopened in Stage
          11d 23h 52m 1
          Niteen Surwase (Inactive) made transition -
          Reopened in Stage In Development
          3s 1
          Niteen Surwase (Inactive) made transition -
          In Development In LB Testing
          2d 20h 20m 3
          Niteen Surwase (Inactive) made transition -
          In LB Testing Pending for Stage Approval
          23d 22h 21m 2
          Niteen Surwase (Inactive) made transition -
          Pending for Stage Approval Approved for Stage
          16d 20h 32m 2
          Rakesh Roy (Inactive) made transition -
          Approved for Stage Stage Testing
          85d 7h 22m 2
          Niteen Surwase (Inactive) made transition -
          Stage Testing Pending for Production Approval
          91d 20h 8m 1
          Niteen Surwase (Inactive) made transition -
          Pending for Production Approval Approved for production
          4s 1
          Niteen Surwase (Inactive) made transition -
          Approved for production In Production Testing
          3s 1
          Niteen Surwase (Inactive) made transition -
          In Production Testing Production Complete
          7s 1
          Niteen Surwase (Inactive) made transition -
          Production Complete Closed
          6s 1

            People

            Assignee:
            prasadp Prasad Pise (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Niteen Surwase (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date: