logo

440 Insecure or unset HTTP headers - Permissions-Policy


Description

The application does not control browser functions in a document or within any iframe.


Impact

Enable functions that allow an attacker to compromise the confidentiality of application users.


Recommendation

- Enable the header permission policy and disable all functions that your application does not need.


Threat

Anonymous attacker from the Internet.


Expected Remediation Time

30 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: H
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: A
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: U

Requirements


Last updated

2024/02/21