View Issue Details

IDProjectCategoryView StatusLast Update
5813Composrcorepublic2024-09-04 21:49
ReporterPDStig Assigned ToChris Graham  
PriorityhighSeverityminor 
Status assignedResolutionopen 
Product Version11.beta1 
Summary5813: Potentially risky wildcard default-src CSP set on several pages
Descriptiondefault-src * data: blob: 'unsafe-inline' is being set on many pages. This might be quite risky especially without a nonce.
TagsRoadmap: v11
Attach Tags
Time estimation (hours)
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

admin

2024-07-27 01:18

administrator   ~8985

Automated message: This issue was created using the Report Issue Wizard on the Composr homesite.

PDStig

2024-07-27 01:22

administrator   ~8986

Possible this may be because of "Permit no JavaScript nonce for injected scripts", which honestly should be disabled by default IMO and users instructed to enable it only if they must for third-party libraries that need it.

PDStig

2024-07-27 01:29

administrator   ~8987

This seems to be happening on a lot of the add and edit screens. Other screens have the proper headers.

PDStig

2024-09-04 21:49

administrator   ~9262

This was mainly a WYSIWYG issue, fixed in 11 beta2, but I still see it on some other screens. Leaving the issue open for now.

Add Note

View Status
Note
Upload Files
Maximum size: 32,768 KiB

Attach files by dragging & dropping, selecting or pasting them.
You are not logged in You are not logged in. This means you will not get any e-mail notifications. And if you reply, we will not know for sure you are the original poster of the issue.

Issue History

Date Modified Username Field Change
2024-07-27 01:18 PDStig Tag Attached: Roadmap: v11
2024-07-27 01:22 PDStig Note Added: 0008986
2024-07-27 01:29 PDStig Note Added: 0008987
2024-07-27 01:29 PDStig Assigned To => Chris Graham
2024-07-27 01:29 PDStig Status Not Assigned => Assigned
2024-07-27 01:29 PDStig Summary Potentially risky wildcard default-src CSP set on several pages => Potentially risky wildcard default-src CSP set on several pages
2024-09-04 21:49 PDStig Note Added: 0009262