CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

PUBLISHEDweakness record
released 2007-05-07 · last modified 2025-12-11
CWE-614 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute - Diagram

Metadata

CWE ID:
CWE-614
摘要:
Variant
结构:
Simple
状态:
Draft
发布日期:
2007-05-07
更新日期:
2025-12-11

名称

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

描述

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

常见后果

范围:
Confidentiality
影响:
Read Application Data
注释:
Omitting the secure flag makes it possible for the user agent to send the cookies in plaintext over an HTTP session.

相关 CWE

相关警报