A recent scan of our Experience Builder sites found three security vulnerabilities with our Content Security Policy.
When tested in Developer Edition 1.11/12, the sites would not function without these settings.
- Why are these settings necessary?
- Are these settings still necessary in more recent versions?
- Could these settings be adjusted more narrowly?
- Are there plans to remove these potential vulnerabilities in future releases?
Edit: For the sake of not publicly posting potential security issues, I have removed the specific issues in the security report.