Description
Browser scripts can read cookies that do not have the HttpOnly attribute.
Potential impact
- XSS can expose session or authentication cookies to an attacker.
Remediation
Set CookieOptions.HttpOnly = true on cookies that client-side scripts do not need to read.
Examples
Before
csharp
response.Cookies.Append("sid", value);
After
csharp
response.Cookies.Append("sid", value, new CookieOptions { HttpOnly = true });
Explanation:
- Before: An attacker exploiting XSS can read a cookie without HttpOnly through client-side scripts.
- After: Enable CookieOptions.HttpOnly for cookies that do not require JavaScript access.