CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Medium

Description

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Potential Impact

How to Fix

Implementation

Always set the secure attribute when the cookie should be sent via HTTPS only.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-614 vulnerabilities in your codebase.

Get Security Assessment