ISSUE-60: Injecting META tags can be an interesting bypass technique, possibly

CSP and META

Injecting META tags can be an interesting bypass technique, possibly

State:
CLOSED
Product:
CSP Level 3
Raised by:
Brad Hill
Opened on:
2014-04-23
Description:
How do we deal with injected META tags in CSP?
Related Actions Items:
No related actions
Related emails:
No related emails

Related notes:

http://www.w3.org/TR/CSP2/#delivery-html-meta-element

Meta must be a child of the <head> element.

Brad Hill, 27 Oct 2014, 04:16:09

Display change log ATOM feed


Daniel Veditz <dveditz@mozilla.com>, Mike West <mkwst@google.com>, Chairs, Wendy Seltzer <wseltzer@w3.org>, Samuel Weiler <weiler@w3.org>, Staff Contacts
Tracker: documentation, (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <w3t-sys@w3.org>.
$Id: 60.html,v 1.1 2020/01/17 08:52:39 carcone Exp $