Insecurely generated cookies - SameSite
Description
The applications cookies are generated without properly setting the SameSite attribute.
Impact
Perform a malicious request via a CSRF attack.
Recommendation
The application must set the SameSite attribute in the cookies with sensitive information.
Threat
Attacker from Internet network performing a CSRF attack.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
029 - Cookies with security attributesRules
Http Cookie Samesite Not InitializedJavascript Insecure Samesite Cookie AttributeJava Cookie Samesite NoneTypescript Insecure Samesite Cookie AttributeJava Cookie Samesite None HeaderConfig Files Cookie Samesite NoneGo Insecure Samesite Cookie AttributePhp Insecure Samesite Cookie AttributeC Sharp Cookie Samesite None SetJava Samesite None SetGo Gin Insecure Samesite Cookie AttributePython Cookie Samesite None Set