Description
Without HttpOnly, browser JavaScript can read a cookie containing an authentication token or session ID. If XSS occurs, an attacker can steal that value and impersonate the user.
Potential impact
- Session hijacking
- Authentication token disclosure
- Account access combined with XSS
Remediation
- Set
HttpOnly=trueon sensitive cookies. - Also apply
Secure=trueand an appropriateSameSitepolicy. - Centralize cookie creation to enforce these security attributes by default.
Examples
Before
java
Cookie cookie = new Cookie("sid", token);
response.addCookie(cookie);
After
java
Cookie cookie = new Cookie("sid", token);
cookie.setHttpOnly(true);
cookie.setSecure(true);
response.addCookie(cookie);
The first example omits HttpOnly, allowing browser scripts to read the sensitive cookie. The second explicitly sets HttpOnly=true and also requires secure transport.