Content-Security-Policy header generation in middleware could be compromised by malicious injections
High severity
GitHub Reviewed
Published
Mar 27, 2024
in
kindspells/astro-shield
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Mar 28, 2024
Published to the GitHub Advisory Database
Mar 29, 2024
Reviewed
Mar 29, 2024
Last updated
Sep 12, 2024
Impact
When the following conditions are met:
Then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts.
Patches
Available in version 1.3.0 .
Workarounds
References
Are there any links users can visit to find out more?
References