•  
      request #9166 Missing HTTPOnly flag on PHP session cookie
    Infos
    #9166
    Thomas Gerbet (tgerbet)
    2016-12-22 13:35
    2016-05-20 15:02
    9436
    Details
    Missing HTTPOnly flag on PHP session cookie

    The session cookie used by PHP can be accessed by client side script code.

    Impact

    The content of the cookie can be stolen by an attacker to mount more complex attacks.
    CVSS3 score: 5.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)

    References

    https://www.owasp.org/index.php/HttpOnly
    https://tools.ietf.org/html/rfc6265#section-5.2.6

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2016-05-23
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2016-05-23 12:02
    Integrated into Tuleap 8.14.99.75.

    • Status changed from Under review to Closed
    • Close date set to 2016-05-23