Property
Languagejava
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

Cookies are being created without explicitly setting the ‘secure’ flag to true, which means they can be transmitted over unencrypted HTTP connections. This exposes sensitive cookie data to network eavesdroppers.

Impact#

If exploited, attackers could intercept cookies containing session or authentication information over insecure networks, leading to account hijacking, session fixation, or exposure of sensitive user data. This compromises both user privacy and application security.