Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22350
HistoryJan 23, 2020 - 6:12 a.m.

Authorization Bypass

2020-01-2306:12:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.001

Percentile

50.8%

secure_headers is vulnerable to authorization bypass. A semicolon character can be used to inject additional values and override arbitrary directives in the Content-Security-Policy header via append/override_content_security_policy_directives.