CSP not consistently applied

Disclosed: 2013-11-30 01:10:30 By janpaul123 To security
Unknown
Vulnerability Details
Also thought I'd formally submitted the issue we discussed yesterday, that sometimes the CSP response headers served are missing for browsers that don't support them, but then the page without these headers can be cached by Cloudflare. This makes it easier to mount a XSS attack.
Actions
View on HackerOne
Report Stats
  • Report ID: 321
  • State: Closed
  • Substate: resolved
  • Upvotes: 28
Share this report