Friction

Pain point · Permissions & security · Blocks work

Default Content Security Policy is too permissive

1 source thread · first seen 2023-01

Summary

Keycloak's default CSP is not locked down enough to protect against XSS and one header applies to every part of the product.

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“The default Content Security Policy (CSP) used by Keycloak is not locked down enough”

Report this item