4 ms·
> If we assume XSS, an attacker could simply inject whatever they want. An attacker can inject whatever they want, but they can't run whatever they want. That'
by spb 11y ago
> If we assume XSS, an attacker could simply inject whatever they want.
An attacker can inject whatever they want, but they can't run whatever they want. That's the purpose of a Content Security Policy: the problem isn't the content of the script being run, it's the context in which that script is being considered.
Because different scripts are given different permissions (eg. access to cookies) based on their domain of origin, the existence of said content must be verified to be true in the context in which it asserts its presence.
It's not a cache-poisoning attack so much as it is a cache-use attack, but it is a legitimate attack.