Invalid Content Security Policy (CSP) Directive Identified in meta Elements Severity: Information Summary# The following CSP directives cannot be used in meta elements and can only be set via headers: frame-ancestors sandbox report-uri Remediation# Move these CSP directives to headers. Classifications# ISO27001-A.14.2.5, OWASP 2017-A6, OWASP 2013-A5, CWE-16, WASC-15 Further Reading# Content Security Policy (CSP) Explained Invicti Security Insights Using Content Security Policy (CSP) to secure web applications Remote Hardware Takeover via Vulnerable Admin Software The dangers of incorrect CSP implementations Leverage Browser Security Features to Secure Your Website Vulnerability Index You can search and find all vulnerabilities Select Category Critical High Medium Low Best Practice Information OR Search Vulnerability Tags OWASP 2013-A5 OWASP 2017-A6 CSP Related Vulnerabilities Blind SQL Injection SQL Injection Local File Inclusion Misconfigured Access-Control-Allow-Origin Header Missing X-Frame-Options Header