Insecurely generated cookies - Secure
Description
The system does not set the Secure attribute for sensitive cookies, which could cause them to be sent through an insecure channel.
Impact
Obtain sensitive information by performing a MiTM attack.
Recommendation
The application must set the Secure attribute in the cookies with sensitive information.
Threat
Unauthorized attacker from adjacent network performing a MitM.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
029 - Cookies with security attributesRules
Http Cookie Missing SecurePython Cookie Secure Set FalseScala Secure Flag Not SetJava Missing Secure Cookie FlagJava Cookie Serializer Secure FalseJavascript Session Cookie Secure FalseKotlin Cookie Missing Secure FlagJava Cookie Secure Flag FalsePhp Set Cookie Without Secure FlagC Sharp Insecure Cookie Secure Flag FalsePhp Cookie Secure False DefaultGo Secure Cookie DisabledJava Missing Secure Cookie Flag ServletTypescript Session Cookie Secure False