Loading...
Loading...
When injecting CSP header values to enable FPS Plugin to work, unnecessary injections may invalidate the application's 'allow inline script' policy, since the more restrictive directive is always applied.
The application's inline scripts will refuse to run since FPS Plugin injects nonce. This breaks user's application.
Server response contains either header from the 'Content-Security-Policy' header family.
None.
CSP header's 'unsafe-inline' and 'nonce' directive injection has been made mutually exclusive.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.