
We have a vulnerability scanning tools which runs through various security issues.
When trying to setup the Content Security policy site setting, which includes the CSP header, all pages in the portal started failing with some styling issues with out of the box web resources. On checking the environment found that the websites Package details are not up to date and trying to upgrade the packages is failing without much error details.
In my organization I am not the power platform admin or Global admin just the System Admin and I am assuming that's why I am not able to upgrade.
I am not able to get any further to close the vulnerabilities.
Appreciate any experience or help to get the environment upgraded and fixing the following issues;
content security policy
Cross-site request forgery (CSRF)
Integrity attribute is missing
Content Type Charset check
I think as a starting point, can you ask your Global Admin to update the packages? and we can see if it resolves after that.
What is the vulnerability issue? And did you see in the Portal Release notes that this is solved by updating the packages? is that it? otherwise it may not affect