PT-2020-21221 · Helmet · Helmet-Csp

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions helmet-csp versions prior to 2.9.1
Description The issue affects the application's Content Security Policy (CSP) by allowing an attacker to remove the default CSP, potentially rendering the application vulnerable to Cross-Site Scripting. This is due to the package's browser sniffing for Firefox deleting the default-src CSP policy.
Recommendations Upgrade to version 2.9.1 or later. As a temporary workaround for versions prior to 2.9.1, set the browserSniff configuration to false.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-C3M8-X3CG-QM2C

Affected Products

Helmet-Csp