Restrict files from CDN in Content Security Policy

Viewed 28

Suppose there are A,B,C,D and E js files present in a CDN but we are using only B and C. Currently script-src in csp allows all js files being downloaded from that CDN but I want to restrict the download only to B and C for my application? Can this be done in Content security policy configuration?

<add name="Content-Security-Policy" value="default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com />
1 Answers
  1. You can use pathes in the Content Security Policy (path should have a trailing slash). For example:

    script-src cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/;

does allow to load any script frim the specified path, for instance https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.min.js or https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.js,
but not https://cdnjs.cloudflare.com/ajax/libs/jquery/2.6.1/jquery.js.

  1. You can specify an exact file name like:

    script-src cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.js;

this will allow the specified script only.

Pls keep in mind that above can be bypassed if you web app (or CDN) allows open redirect, because CSP does not checks pathes in case of redirects. So:

<script src='https://your_domain.com.com/?redirect=https://cdnjs.cloudflare.com/ajax/libs/vue/1.0.4/vue.js'>

will allow to load vue.js script.

Related