ISSUE-60: Injecting META tags can be an interesting bypass technique, possibly
CSP and META
Injecting META tags can be an interesting bypass technique, possibly
- State:
- CLOSED
- Product:
- CSP Level 3
- Raised by:
- Brad Hill
- Opened on:
- 2014-04-23
- Description:
- How do we deal with injected META tags in CSP?
- Related Actions Items:
- No related actions
- Related emails:
- No related emails
Related notes:
http://www.w3.org/TR/CSP2/#delivery-html-meta-element
Meta must be a child of the <head> element.
Display change log