[ad_1]
[ad_2]
Good morning. I'm getting a bit of pushback from our web folks about some unsafe headers that they have enabled. The ones I've focused on are 'unsafe-inline' and 'unsafe-eval'. I'm however having difficulty explaining the potential outcome of using these directives. Additionally, if you know of anyone popped through these headers — that information would be beneficial. I'm pretty sure these are dangerous, I'm just not sure HOW dangerous