10010Cookie No HttpOnly Flag

PUBLISHEDsecurity alertLow
Passive

Metadata

Alert ID:
10010
Risk:
Low
Type:
Passive

摘要

A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.

解决方案

Ensure that the HttpOnly flag is set for all cookies.

参考