#24 Bad cookie attributes

Closed
opened 5 years ago by sindre · 0 comments
sindre commented 5 years ago

Cookies holding session data should ideally be both Http-Only and Http-Secure, but are neither.

Cookies holding session data should ideally be both Http-Only and Http-Secure, but are neither.
sindre added this to the Required fixes milestone 5 years ago
sindre added the
webpy
label 5 years ago
sindre added the
bug
label 5 years ago
sindre added the
security misconfiguration
label 5 years ago
sindre removed this from the Required fixes milestone 5 years ago
sindre added this to the Optional vulnerabilities milestone 5 years ago
Sign in to join this conversation.
Loading…
Cancel
Save
There is no content yet.