Remediating Cross-Domain Subresource Integrity (SRI) Checks

Cross-Domain Subresource (SRI) Checks are scanned as part of the Cross-site Scripting Security Tests used to evaluate the Web Application Security Risk Vector.

With this security test, we assess whether external resources include a valid integrity attribute. The grade is based on a weighted observation of vulnerable (no SRI) vs. not vulnerable (has SRI) resources.

Need to fix this?

  • Avoid loading scripts from third-party resources to prevent exposure to content and JavaScript manipulation by third parties or in case of a network compromise. 
  • If loading third-party scripts is necessary, you should use subresource integrity (SRI) tags whenever possible.

How can I check the Cross-Domain Subresource Integrity setting in my web application? Use Chrome Developer Tools to inspect script tags and confirm presence of the integrity attribute.

Does this impact my WAS Risk Vector Grade? Yes.

Possible Grades:

  • Good: Relevant SRI checks are implemented. (Weight = 0)
    Table snippet showing a finding graded "Good," severity "Minor," and "Impacts Risk Vector Grade: No: Remediated"

     
  • Fair: Few or no SRI checks are implemented. (Weight = >0 and 0.1)
    Table snippet showing a finding graded "Good," severity "Minor," and "Impacts Risk Vector Grade: Yes"

What will I see in the Portal?

Screenshot of a Remediations panel describing the "Missing integrity attribute" issue and its remediation tip

Issue: Missing integrity attribute

Details: The page does not include an integrity attribute on cross-domain fetching of scripts.

Good to Know:

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.