Insecurely generated cookies - HttpOnly
Description
The applications cookies are generated without properly setting the HttpOnly attribute.
Impact
Obtain sensitive information by performing a XSS attack.
Recommendation
The application must set the HttpOnly attribute in the cookies with sensitive information.
Threat
Authorized attacker from internet network performing a XSS attack.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
029 - Cookies with security attributesRules
Http Cookie Missing HttponlyScala Cookie Missing HttponlyRuby Sensitive Cookie Without HttponlyTypescript Session Cookie Http Only FalsePhp Set Cookie Without HttponlyGo Http Only DisabledPhp Session Cookie Missing HttponlyKotlin Cookie Missing HttponlyJavascript Httponly Flag Not SetC Sharp Http Only False CookiePython Cookie Httponly FalseJavascript Session Cookie Http Only FalseTypescript Httponly Flag Not SetJava Http Only Not Set