How to fix Content-Security-Policy HTTP Security Header Not Detected issue ?

ABHISHEK KUMAR 20 Reputation points
2023-11-27T19:43:24.6233333+00:00

Security team has observed this threats on multiple machine ?

Threat

"The HTTP Content-Security-Policy response header allows web site administrators to control resources the user agent is allowed to load for a given page. This helps guard against cross-site scripting attacks (XSS).

QID Detection Logic:

This QID detects the absence of the Content-Security-Policy HTTP header by transmitting a GET request."

"Content-Security-Policy HTTP Header missing on port 8530.

GET / HTTP/1.1

Host: tpr-win-jump-01.c.tap-shared-srv.internal:8530

Connection: Keep-Alive"

"Content-Security-Policy HTTP Header missing on port 80.

GET / HTTP/1.1

Host: tpr-cvlt-mstr1.c.tap-shared-srv.internal

Connection: Keep-Alive"

"Content-Security-Policy HTTP Header missing on port 80.

GET / HTTP/1.1

Host: tpr-win-jump-02.c.tap-shared-srv.internal

Connection: Keep-Alive"

"Content-Security-Policy HTTP Header missing on port 443.

GET / HTTP/1.1

Host: tpr-win-jump-02.c.tap-shared-srv.internal

Connection: Keep-Alive"

"Content-Security-Policy HTTP Header missing on port 80.

GET / HTTP/1.1

Host: tpr-ad-02.c.tap-shared-srv.internal

Connection: Keep-Alive"

Windows for business Windows Server User experience Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.