Implement Content-Security-Policy header for ports 2083, 2087 and 2096 to pass CPI scans
Open Discussion
As a system administrator, I would like to see content security policy header implemented for ports 2083, 2087, and 2096 so that my servers are able to pass PCI compliance.
Recent PCI scans are failing because ports 2083, 2087 and 2096 do not block frame clickjacking using the Content-Security-Policy header - even though the obsolete X-Frame-Options is enabled. Please implement that option, at least for frame-ancestors.
Replies have been locked on this page!