Description
A cookie without Secure can be sent over HTTP and exposed to an attacker observing the network.
Potential impact
- A stolen session or authentication cookie can lead to account takeover.
Remediation
Set CookieOptions.Secure = true or use CookieSecurePolicy.Always for sensitive cookies.
Examples
Before
csharp
response.Cookies.Append("sid", value);
After
csharp
response.Cookies.Append("sid", value, new CookieOptions { Secure = true });
Explanation:
- Before: Without Secure, the cookie may be sent over plaintext HTTP.
- After: Enable CookieOptions.Secure or CookieSecurePolicy.Always for sensitive cookies.