Uploaded image for project: 'Rules Repository'
  1. Rules Repository
  2. RSPEC-2092

Creating cookies without the "secure" flag is security-sensitive

    Details

    • Message:
      Make sure creating this cookie without the "secure" flag is safe here.
    • Default Severity:
      Minor
    • Impact:
      Low
    • Likelihood:
      Low
    • Default Quality Profiles:
      Sonar way
    • Targeted languages:
      C++, Objective-C, Python, VB.Net
    • Covered Languages:
      C#, Java, PHP
    • Remediation Function:
      Constant/Issue
    • Constant Cost:
      5min
    • Analysis Level:
      Semantic Analysis
    • Analysis Scope:
      Main Sources
    • Common Rule:
      Yes
    • CWE:
      CWE-614, CWE-311, CWE-315
    • OWASP:
      A2, A3
    • SANS Top 25:
      Porous Defenses
    • FindSecBugs:
      INSECURE_COOKIE

      Description

      See

        Attachments

          Issue Links

          1.
          PHP RSPEC-3761 Language-Specification Active Unassigned
          2.
          C# RSPEC-4556 Language-Specification Active Unassigned
          3.
          Java RSPEC-4557 Language-Specification Active Unassigned

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                ann.campbell.2 Ann Campbell
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated: