Skip to content

Update: Cross_Site_Scripting_Prevention_Cheat_Sheet #376

@calabacito

Description

@calabacito

What is missing or needs to be updated?

We should update Bonus Rule #4: Use the X-XSS-Protection Response Header

How should this be resolved?

Browsers don't give proper support anymore:
Chrome has XSS Auditor Removed: https://www.chromestatus.com/feature/5021976655560704
Firefox have not, and will not implement X-XSS-Protection: https://bugzilla.mozilla.org/show_bug.cgi?id=528661
Edge have retired their XSS filter: https://blogs.windows.com/windowsexperience/2018/07/25/announcing-windows-10-insider-preview-build-17723-and-build-18204/

Some of the links were provided via: metabase/metabase#11444

Thanks,
Ariel Coronel

Metadata

Metadata

Assignees

No one assigned

    Labels

    ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.HELP_WANTEDIssue for which help is wanted to do the job.UPDATE_CSIssue about the update/refactoring of a existing cheat sheet.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions