X-XSS-Protection Header is Missing
Impact: Informational
Description
This issue has been retired in favour of X-XSS-Protection Header is Set
The HTTP X-XSS-Protection
response header is a feature of Internet Explorer, Chrome and Safari that stops pages from loading when they detect reflected cross-site scripting (XSS) attacks. Mozilla
Recommendation
Configure your server to send this header for all pages. You can see references for possible values.
References
- Mozilla: Web Security
- Mozilla: X-XSS-Protection
- OWASP github: Remove X-XSS-Protection Response Header
👉 You might also like:
X-XSS-Protection Header is Set - Vulnerability
X-Content-Type-Options Header is Missing - Vulnerability
X-Frame-Options Header is Missing - Vulnerability
Content-Security-Policy Header is Missing - Vulnerability
Last updated on November 10, 2021