Skip to content

X-XSS-Protection vulnerability on old IE #1770

@EvanHahn

Description

@EvanHahn

On old versions of Internet Explorer, X-XSS-Protection: 1; mode=block creates a vulnerability (see here and here), and so the header is should be set to 0 to mitigate that vulnerability.

Metadata

Metadata

Assignees

Labels

documentationNon-code related changessecurityIssue with security impact

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions