build1 publisher
A Raxis pentester walked attacker JavaScript past a nonce-based CSP through googletagmanager.com
The strict-dynamic directive passes a script's trust to everything that script loads, and Ryan Chaplin of Raxis used that rule to get an XSS payload executing under a nonce-based policy that had blocked it.
Publishers:dev.to
Reality
- Evidence55
- Adoption30
- Hype gap+22
- Incentives62
- Confidence50