Mondoo Docs

HTTP header X-XSS-Protection, which is now outdated (replaced by CSP)

and may even cause security vulnerabilities

NetworkPrivate Resource

HTTP header X-XSS-Protection, which is now outdated (replaced by CSP)

and may even cause security vulnerabilities

Min version: 9.0.0Defaults: enabled mode report

Relationships

Mini Map
Network
2 resources · 2 relationshipsClick to select, expand fields to see properties.

Fields (3)

FieldTypeDescription
enabledrequired
intWhether the header is enabled (Enabled when the header value is set to 1; disabled if set to 0)
moderequired
stringMode for XSS filtering
reportrequired
stringReport endpoint for violations (Chromium only)