Details
Alert ID 10038-2
Alert Type Passive
Status release
Risk Informational
CWE 693
WASC 15
Technologies Targeted All
Tags CWE-693
OWASP_2017_A06
OWASP_2021_A05
More Info Scan Rule Help

Summary

The “X-Content-Security-Policy” and “X-WebKit-CSP” headers are no longer recommended.

Solution

Ensure that your web server, application server, load balancer, etc. is configured to set the Content-Security-Policy header.

Other Info

References

Code

org/zaproxy/zap/extension/pscanrules/ContentSecurityPolicyMissingScanRule.java