# Is unsafe-eval required for script-src in the content-security-policy for Kibana 6.7.1?

**URL:** <https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298>\
**Category:** Kibana\
**Created:** [April 3, 2020, 12:36am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298 "2020-04-03T00:36:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cjin62](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjin62/32/66480_2.png) [@cjin62](https://discuss.elastic.co/u/cjin62)\
**Post date:** [April 3, 2020, 12:36am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/1 "2020-04-03T00:36:58Z")

</div>

When loading the Kibana dashboard home page, unsafe-eval shows up for script-src:

content-security-policy: script-src 'unsafe-eval' 'self'

Is unsafe-eval required for Kibana dashboard to work? Or only needed for certain functions in the Kibana dashboard?

We have the following menus/functions on the left hand side:

- Discover
- Visualize
- Dashboard
- Timelion
- Alerting
- Dev Tools
- Management
- Security

Usually, for 'default-src', 'script-src' and 'object-src', unsafe-eval is considered insecure and should be avoided... As banning the ability to execute strings makes it much more difficult for an attacker to execute unauthorized code on the site...

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 3, 2020, 2:36am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/2 "2020-04-03T02:36:30Z")

</div>

Hi @cjin62,

Welcome to our community! Please check if this is the issue you are seeing or if it is something else:

> <https://github.com/elastic/kibana/issues/30468>
>
> IMPORTANT
> It is expected for you to see the following error and then console output in your browser, it does not allude...

Thanks!  
Liza

---

<div class="post-metadata">

**Author:** ![cjin62](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjin62/32/66480_2.png) [@cjin62](https://discuss.elastic.co/u/cjin62)\
**Post date:** [April 3, 2020, 5:05am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/3 "2020-04-03T05:05:56Z")

</div>

Hi @LizaD - Thank you for the quick reply. I already reviewed that post before I raised my question - it unfortunately does not address my question.

What I'd like to do is to set the `csp.rules` parameter in the kibana.yml file to no longer have unsafe-eval for script-src - to make it more secure:

[https://www.elastic.co/guide/en/kibana/6.7/settings.html](https://www.elastic.co/guide/en/kibana/6.7/settings.html)

However, I do not know whether removing unsafe-eval from script-src will cause any issues with the list of Kibana functions below:

- Discover
- Visualize
- Dashboard
- Timelion
- Alerting
- Dev Tools
- Management
- Security

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 6, 2020, 6:31pm UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/4 "2020-04-06T18:31:45Z")

</div>

Thanks @cjin62,

Let me check with one of security experts to see if they can help.

@jportner can you help answer this?

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [April 6, 2020, 6:47pm UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/5 "2020-04-06T18:47:23Z")

</div>

Hi @cjin62,

We are aware that Kibana's default Content-Security-Policy is not as strict as desired. Unfortunately, Kibana currently requires "unsafe-eval" to function. We do have an open enhancement issue on GitHub if you'd like to follow it for updates: [https://github.com/elastic/kibana/issues/36311](https://github.com/elastic/kibana/issues/36311)

Best,  
-Joe

---

<div class="post-metadata">

**Author:** ![cjin62](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjin62/32/66480_2.png) [@cjin62](https://discuss.elastic.co/u/cjin62)\
**Post date:** [April 17, 2020, 1:00am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/6 "2020-04-17T01:00:38Z")

</div>

Thank you for the info Joe. I have subscribed to that issue now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2020, 1:00am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/7 "2020-05-15T01:00:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
