Vulnerabilities/

Cookie without Secure Flag

Severity:
Low

Description

The absence of the Secure flag in cookies allows them to be transmitted over unencrypted connections, making them vulnerable to interception by attackers conducting man-in-the-middle (MitM) attacks. A cookie with the Secure flag is only sent to the server with encrypted requests over HTTPS, ensuring its confidentiality and integrity.

Recommendation

To enhance security, always set the Secure flag for cookies, especially for those containing sensitive information such as session tokens or user credentials. This ensures that the cookies are only transmitted over secure, encrypted connections, mitigating the risk of interception by attackers.

References

Related Issues

Tags:
HTTP Headers
SSL/TLS
Cookie
Man-in-the-middle Attack
Application Misconfiguration
Anything's wrong? Let us know Last updated on May 13, 2024

Use SmartScanner Free version to test for this issue

Download