10038-2Obsolete Content Security Policy (CSP) Header Found

PUBLISHEDsecurity alertInformational
Passive

Metadata

Alert ID:
10038-2
Risk:
Informational
Type:
Passive

Summary

The “X-Content-Security-Policy” and “X-WebKit-CSP” headers are no longer recommended.

Solution

Ensure that your web server, application server, load balancer, etc. is configured to set the Content-Security-Policy header.

References