440 – Insecure or unset HTTP headers - Permissions-Policy
Description
The application does not control browser functions in a document or within any iframe.
Impact
Enable functions that allow an attacker to compromise the confidentiality of application users.
Recommendation
- Enable the header permission policy and disable all functions that your application does not need.
Threat
Anonymous attacker from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: H
- Attack Requirements: N
- Privileges required: N
- User interaction: A
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: U