Replies: 1 comment
-
Changes to ASVS 5.0 Requirements specific to CSP documented within #1406 ASVS 5.0 Requirement for the iFrame |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
"2.3 Security Headers" of MVSP is reproduced below:
2.3 Security Headers
Apply appropriate security headers to reduce the application attack surface and limit post exploitation:
* Set a minimally permissive Content Security Policy
* Limit the ability to iframe sensitive application content where appropriate
The parent of this [MVSP] issue is #1151.
Beta Was this translation helpful? Give feedback.
All reactions