Implement Content-Security-Policy header for ports 2083, 2087 and 2096 to pass CPI scans
Open Discussion
As a system administrator, I would like to see content security policy header implemented for ports 2083, 2087, and 2096 so that my servers are able to pass PCI compliance.
-----------------------------------------------------------
Recent PCI scans are failing because ports 2083, 2087 and 2096 do not block frame clickjacking using the Content-Security-Policy header - even though the obsolete X-Frame-Options is enabled. Please implement that option, at least for frame-ancestors.
Replies have been locked on this page!