https://www.ethiopianairlines.com/book/booking/flight

Submitted URL:
https://www.ethiopianairlines.com/book/booking/flight
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 3 found

HTTP response headers that can harden the security of a web application

Learn more...
NameValueSupportInfo
Strict-Transport-Securitymax-age=2592000GoodDeclare that a website is only accessible over a secure connection (HTTPS).

Click to learn more...
X-Frame-OptionsSAMEORIGINGoodIndicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>.

Click to learn more...
X-Content-Type-OptionsGoodIndicate that the MIME types advertised in the Content-Type headers should be followed and not be changed.

Click to learn more...
Content-Security-Policyscript-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com https://upgrade.plusgrade.com/ https://www.googletagmanager.com/ https://api.pushio.com/ https://aswpsdkeu.com/ https://analytics.google.com/ https://js.monitor.azure.com/ https://*.creativecdn.com https://bat.bing.com https://connect.facebook.net https://apps.mypurecloud.de https://cdnjs.cloudflare.com https://mc.yandex.ru https://googleads.g.doubleclick.net https://*.cloudfront.net https://www.clarity.ms https://www.mczbf.com https://w.usabilla.com https://image.et.ethiopianairlines.com https://*.evergage.com https://*.evgnet.com; style-src 'self' https://upgrade-cdn-prd.plusgrade.com/ 'unsafe-inline'; img-src 'self' 'unsafe-inline' 'unsafe-eval' https://upgrade-cdn-prd.plusgrade.com/ https://www.ethiopianairlines.com/ https://etwebcms.azurewebsites.net/ *.googleapis.com *.gstatic.com www.google.com https://www.google.com.et/ https://pos.baidu.com/ apis.google.com *.google-analytics.com https://www.facebook.com/ https://www.googletagmanager.com/ https://*.bing.com https://mc.yandex.ru https://*.clarity.ms https://fast.nexx360.io https://image.et.ethiopianairlines.com data:; connect-src 'self' wss://ws.salecycle.com/ https://*.creativecdn.com/ *.google-analytics.com https://www.google.com/ https://google.com/ https://analytics.google.com/ https://www.googletagmanager.com/ https://eastus-8.in.applicationinsights.azure.com/ https://api.mypurecloud.de https://mc.yandex.ru https://*.clarity.ms https://*.bing.com https://stats.g.doubleclick.net https://www.facebook.com https://www.mczbf.com https://*.evergage.com; frame-src 'self' www.google.com https://live.tourdash.com/ https://www.youtube.com/ https://etwebcms.azurewebsites.net/ https://www.googletagmanager.com https://td.doubleclick.net/ https://mc.yandex.ru https://www.facebook.com https://*.creativecdn.com https://*.google.com; font-src 'self' https://fonts.gstatic.com/; default-src 'self'; media-src 'self'GoodControl resources the user agent is allowed to load for a given page.

Click to learn more...
Referrer-PolicyGoodControl how much referrer information should be included with requests.

Click to learn more...
Clear-Site-DataGoodControl the data stored by a client browser for their origins.

Click to learn more...
X-Permitted-Cross-Domain-PoliciesGoodControl whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains.

Click to learn more...
Permissions-PolicyNewAllow and deny the use of browser features in a document or iframe.

Click to learn more...
Cross-Origin-Embedder-PolicyNewConfigure embedding cross-origin resources into the document.

Click to learn more...
Cross-Origin-Opener-PolicyNewEnsure a top-level document does not share a browsing context group with cross-origin documents.

Click to learn more...
Cross-Origin-Resource-PolicyNewRequest that the browser blocks no-cors cross-origin/cross-site requests to the given resource.

Click to learn more...
X-XSS-ProtectionDeprecatedDeprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks.

Click to learn more...
Feature-PolicyDeprecatedDeprecated. Replaced by the Permissions-Policy header.

Click to learn more...
Expect-CTDeprecatedDeprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements.

Click to learn more...
Public-Key-PinsDeprecatedDeprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates.

Click to learn more...

Security Violations · 8 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://www.ethiopianairlines.com/book/booking/flight
Description
Refused to load the image 'https://mc.yandex.com/sync_cookie_image_check' because it violates the following Content Security Policy directive: "img-src 'self' 'unsafe-inline' 'unsafe-eval' https://upgrade-cdn-prd.plusgrade.com/ https://www.ethiopianairlines.com/ https://etwebcms.azurewebsites.net/ *.googleapis.com *.gstatic.com www.google.com https://www.google.com.et/ https://pos.baidu.com/ apis.google.com *.google-analytics.com https://www.facebook.com/ https://www.googletagmanager.com/ https://*.bing.com https://mc.yandex.ru https://*.clarity.ms https://fast.nexx360.io https://image.et.ethiopianairlines.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.ethiopianairlines.com/book/booking/flight
Description
Refused to load the image 'https://mc.yandex.com/sync_cookie_image_check' because it violates the following Content Security Policy directive: "img-src 'self' 'unsafe-inline' 'unsafe-eval' https://upgrade-cdn-prd.plusgrade.com/ https://www.ethiopianairlines.com/ https://etwebcms.azurewebsites.net/ *.googleapis.com *.gstatic.com www.google.com https://www.google.com.et/ https://pos.baidu.com/ apis.google.com *.google-analytics.com https://www.facebook.com/ https://www.googletagmanager.com/ https://*.bing.com https://mc.yandex.ru https://*.clarity.ms https://fast.nexx360.io https://image.et.ethiopianairlines.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.ethiopianairlines.com/book/booking/flight
Description
Refused to load the image 'https://mc.yandex.com/metrika/advert.gif' because it violates the following Content Security Policy directive: "img-src 'self' 'unsafe-inline' 'unsafe-eval' https://upgrade-cdn-prd.plusgrade.com/ https://www.ethiopianairlines.com/ https://etwebcms.azurewebsites.net/ *.googleapis.com *.gstatic.com www.google.com https://www.google.com.et/ https://pos.baidu.com/ apis.google.com *.google-analytics.com https://www.facebook.com/ https://www.googletagmanager.com/ https://*.bing.com https://mc.yandex.ru https://*.clarity.ms https://fast.nexx360.io https://image.et.ethiopianairlines.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://js.monitor.azure.com/scripts/b/ai.2.min.js
Description
Refused to connect to 'https://mc.yandex.com/watch/93581633?wmode=7&page-url=https%3A%2F%2Fwww.ethiopianairlines.com%2Fbook%2Fbooking%2Fflight&charset=utf-8&uah=chm%0A%3F0&browser-info=pv%3A1%3Avf%3A14pwap7gbnl70a58u0m6s2b47zyz%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1541%3Acn%3A1%3Adp%3A0%3Als%3A1687448109646%3Ahid%3A813792721%3Az%3A0%3Ai%3A20241211172702%3Aet%3A1733938022%3Ac%3A1%3Arn%3A284779197%3Arqn%3A1%3Au%3A1733938022825630009%3Aw%3A800x600%3As%3A1x1x24%3Ask%3A1%3Afp%3A1667%3Awv%3A2%3Ads%3A0%2C111%2C776%2C54%2C3%2C0%2C%2C2891%2C237%2C%2C%2C%2C3957%3Aco%3A0%3Acpf%3A1%3Antf%3A1%3Ans%3A1733938016424%3Arqnl%3A1%3Ast%3A1733938022%3At%3ABook%20your%20Flight%20%7C%20Ethiopian%20Airlines&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)rcm(1)cdl(na)eco(42533376)ti(1)' because it violates the following Content Security Policy directive: "connect-src 'self' wss://ws.salecycle.com/ https://*.creativecdn.com/ *.google-analytics.com https://www.google.com/ https://google.com/ https://analytics.google.com/ https://www.googletagmanager.com/ https://eastus-8.in.applicationinsights.azure.com/ https://api.mypurecloud.de https://mc.yandex.ru https://*.clarity.ms https://*.bing.com https://stats.g.doubleclick.net https://www.facebook.com https://www.mczbf.com https://*.evergage.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://js.monitor.azure.com/scripts/b/ai.2.min.js
Description
Refused to connect to 'https://mc.yandex.com/watch/93581633?wmode=7&page-url=https%3A%2F%2Fwww.ethiopianairlines.com%2Fbook%2Fbooking%2Fflight&charset=utf-8&uah=chm%0A%3F0&browser-info=pv%3A1%3Avf%3A14pwap7gbnl70a58u0m6s2b47zyz%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1541%3Acn%3A1%3Adp%3A0%3Als%3A1687448109646%3Ahid%3A813792721%3Az%3A0%3Ai%3A20241211172702%3Aet%3A1733938022%3Ac%3A1%3Arn%3A284779197%3Arqn%3A1%3Au%3A1733938022825630009%3Aw%3A800x600%3As%3A1x1x24%3Ask%3A1%3Afp%3A1667%3Awv%3A2%3Ads%3A0%2C111%2C776%2C54%2C3%2C0%2C%2C2891%2C237%2C%2C%2C%2C3957%3Aco%3A0%3Acpf%3A1%3Antf%3A1%3Ans%3A1733938016424%3Arqnl%3A1%3Ast%3A1733938022%3At%3ABook%20your%20Flight%20%7C%20Ethiopian%20Airlines&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)rcm(1)cdl(na)eco(42533376)ti(1)' because it violates the document's Content Security Policy.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://js.monitor.azure.com/scripts/b/ai.2.min.js
Description
Refused to connect to 'https://mc.yandex.com/watch/93581633?wmode=7&page-url=https%3A%2F%2Fwww.ethiopianairlines.com%2Fbook%2Fbooking%2Fflight&charset=utf-8&uah=chm%0A%3F0&browser-info=pv%3A1%3Avf%3A14pwap7gbnl70a58u0m6s2b47zyz%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1541%3Acn%3A1%3Adp%3A0%3Als%3A1687448109646%3Ahid%3A813792721%3Az%3A0%3Ai%3A20241211172702%3Aet%3A1733938022%3Ac%3A1%3Arn%3A284779197%3Arqn%3A1%3Au%3A1733938022825630009%3Aw%3A800x600%3As%3A1x1x24%3Ask%3A1%3Afp%3A1667%3Awv%3A2%3Ads%3A0%2C111%2C776%2C54%2C3%2C0%2C%2C2891%2C237%2C%2C%2C%2C3957%3Aco%3A0%3Acpf%3A1%3Antf%3A1%3Ans%3A1733938016424%3Arqnl%3A1%3Ast%3A1733938022%3At%3ABook%20your%20Flight%20%7C%20Ethiopian%20Airlines&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)rcm(1)cdl(na)eco(42533376)ti(2)' because it violates the following Content Security Policy directive: "connect-src 'self' wss://ws.salecycle.com/ https://*.creativecdn.com/ *.google-analytics.com https://www.google.com/ https://google.com/ https://analytics.google.com/ https://www.googletagmanager.com/ https://eastus-8.in.applicationinsights.azure.com/ https://api.mypurecloud.de https://mc.yandex.ru https://*.clarity.ms https://*.bing.com https://stats.g.doubleclick.net https://www.facebook.com https://www.mczbf.com https://*.evergage.com".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://mc.yandex.ru/metrika/tag.js
Description
Refused to load the script 'https://mc.yandex.com/watch/93581633?callback=_ymjsp619910415&page-url=https%3A%2F%2Fwww.ethiopianairlines.com%2Fbook%2Fbooking%2Fflight&charset=utf-8&uah=chm%0A%3F0&browser-info=pv%3A1%3Avf%3A14pwap7gbnl70a58u0m6s2b47zyz%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen-US%3Av%3A1541%3Acn%3A1%3Adp%3A0%3Als%3A1687448109646%3Ahid%3A813792721%3Az%3A0%3Ai%3A20241211172702%3Aet%3A1733938022%3Ac%3A1%3Arn%3A284779197%3Arqn%3A1%3Au%3A1733938022825630009%3Aw%3A800x600%3As%3A1x1x24%3Ask%3A1%3Afp%3A1667%3Awv%3A2%3Ads%3A0%2C111%2C776%2C54%2C3%2C0%2C%2C2891%2C237%2C%2C%2C%2C3957%3Aco%3A0%3Acpf%3A1%3Antf%3A1%3Ans%3A1733938016424%3Arqnl%3A1%3Ast%3A1733938022%3At%3ABook%20your%20Flight%20%7C%20Ethiopian%20Airlines&t=gdpr(14)clc(0-0-0)rqnt(1)aw(1)rcm(1)cdl(na)eco(42533376)ti(3)&wmode=5' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com https://upgrade.plusgrade.com/ https://www.googletagmanager.com/ https://api.pushio.com/ https://aswpsdkeu.com/ https://analytics.google.com/ https://js.monitor.azure.com/ https://*.creativecdn.com https://bat.bing.com https://connect.facebook.net https://apps.mypurecloud.de https://cdnjs.cloudflare.com https://mc.yandex.ru https://googleads.g.doubleclick.net https://*.cloudfront.net https://www.clarity.ms https://www.mczbf.com https://w.usabilla.com https://image.et.ethiopianairlines.com https://*.evergage.com https://*.evgnet.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...
Resource
https://www.ethiopianairlines.com/book/booking/flight
Description
Refused to load the image 'https://ib.adnxs.com/setuid?entity=315&code=WU1DKV2NWFHcxXIFI2o6sWMFOd4gu-bXFnMszy81ZK0&consent=1' because it violates the following Content Security Policy directive: "img-src 'self' 'unsafe-inline' 'unsafe-eval' https://upgrade-cdn-prd.plusgrade.com/ https://www.ethiopianairlines.com/ https://etwebcms.azurewebsites.net/ *.googleapis.com *.gstatic.com www.google.com https://www.google.com.et/ https://pos.baidu.com/ apis.google.com *.google-analytics.com https://www.facebook.com/ https://www.googletagmanager.com/ https://*.bing.com https://mc.yandex.ru https://*.clarity.ms https://fast.nexx360.io https://image.et.ethiopianairlines.com data:".
Content Security PolicyControl resources the user agent is allowed to load for a given page.

Click to learn more...

Certificates · 21 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
ethiopianairlines.comAug 30, 2024, 00:00:00Aug 15, 2025, 23:59:59
api.push.ioJul 30, 2024, 00:00:00Jul 29, 2025, 23:59:59
*.google-analytics.comNov 4, 2024, 08:37:47Jan 27, 2025, 08:37:46
aswpsdkeu.comJun 26, 2024, 00:00:00Jun 4, 2025, 23:59:59
js.monitor.azure.comNov 19, 2024, 03:45:33May 18, 2025, 03:45:33
www.google.comNov 4, 2024, 08:39:37Jan 27, 2025, 08:39:36
1589314308.rsc.cdn77.orgOct 16, 2024, 08:58:18Jan 14, 2025, 08:58:17
www.bing.comSep 16, 2024, 23:16:19Mar 15, 2025, 23:16:19
*.facebook.comSep 19, 2024, 00:00:00Dec 18, 2024, 23:59:59
mypurecloud.deJul 19, 2024, 00:00:00Aug 16, 2025, 23:59:59