<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Mitigate Multiple Security Risks in Default CSP Configuration for Mobile Access Portal? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Mitigate-Multiple-Security-Risks-in-Default-CSP/m-p/224144#M3307</link>
    <description>&lt;P&gt;Please review&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178514" target="_self"&gt;&lt;SPAN&gt;sk178514&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2024 08:29:46 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2024-08-21T08:29:46Z</dc:date>
    <item>
      <title>How to Mitigate Multiple Security Risks in Default CSP Configuration for Mobile Access Portal?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Mitigate-Multiple-Security-Risks-in-Default-CSP/m-p/224123#M3306</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We’re using Checkpoint's Mobile Access Portal, and during a security scan with Panoray, we identified potential vulnerabilities related to the default CSP configuration:&lt;/P&gt;&lt;P&gt;Checkpoint Gateway Version : R81.10&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;Content-Security-Policy: default-src 'self' wss: localhost:14186 &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; &lt;A href="http://www.gstatic.com" target="_blank"&gt;www.gstatic.com&lt;/A&gt; 'unsafe-inline' 'unsafe-eval'; img-src https: 'self' data:; font-src 'self' data: fonts.gstatic.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The detected issues include:&lt;BR /&gt;1. The use of 'unsafe-inline' and `'unsafe-eval'`, which could increase the risk of XSS attacks.&lt;BR /&gt;2. The default-src directive allowing resources from &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; and `&lt;A href="http://www.gstatic.com" target="_blank"&gt;www.gstatic.com&lt;/A&gt;`, potentially broadening the attack surface.&lt;BR /&gt;3. Allowing data: in `img-src`, which may introduce some risk, albeit lower.&lt;BR /&gt;4. Allowing data: in `font-src`, which could also pose risks, and might be better managed by restricting resource sources.&lt;/P&gt;&lt;P&gt;Since these vulnerabilities were flagged by Panoray, we’re looking for recommendations on how to mitigate these risks within the default configuration. Specifically, how can we safely address the use of 'unsafe-inline' and `'unsafe-eval'`, and what are the best practices for securely managing external resource sources?&lt;/P&gt;&lt;P&gt;Any advice or configuration recommendations would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 03:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Mitigate-Multiple-Security-Risks-in-Default-CSP/m-p/224123#M3306</guid>
      <dc:creator>ahan</dc:creator>
      <dc:date>2024-08-21T03:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to Mitigate Multiple Security Risks in Default CSP Configuration for Mobile Access Portal?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Mitigate-Multiple-Security-Risks-in-Default-CSP/m-p/224144#M3307</link>
      <description>&lt;P&gt;Please review&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178514" target="_self"&gt;&lt;SPAN&gt;sk178514&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 08:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Mitigate-Multiple-Security-Risks-in-Default-CSP/m-p/224144#M3307</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-21T08:29:46Z</dc:date>
    </item>
  </channel>
</rss>

