How to fix Content-Security-Policy HTTP Security Header Not Detected issue ?
Security team has observed this threats on multiple machine ?
Threat
"The HTTP Content-Security-Policy response header allows web site administrators to control resources the user agent is allowed to load for a given page. This helps guard against cross-site scripting attacks (XSS).
QID Detection Logic:
This QID detects the absence of the Content-Security-Policy HTTP header by transmitting a GET request."
"Content-Security-Policy HTTP Header missing on port 8530.
GET / HTTP/1.1
Host: tpr-win-jump-01.c.tap-shared-srv.internal:8530
Connection: Keep-Alive"
"Content-Security-Policy HTTP Header missing on port 80.
GET / HTTP/1.1
Host: tpr-cvlt-mstr1.c.tap-shared-srv.internal
Connection: Keep-Alive"
"Content-Security-Policy HTTP Header missing on port 80.
GET / HTTP/1.1
Host: tpr-win-jump-02.c.tap-shared-srv.internal
Connection: Keep-Alive"
"Content-Security-Policy HTTP Header missing on port 443.
GET / HTTP/1.1
Host: tpr-win-jump-02.c.tap-shared-srv.internal
Connection: Keep-Alive"
"Content-Security-Policy HTTP Header missing on port 80.
GET / HTTP/1.1
Host: tpr-ad-02.c.tap-shared-srv.internal
Connection: Keep-Alive"