Sensitive cookies without HttpOnly

Prevent script access to sensitive cookies with HttpOnly

Description

Without HttpOnly, browser JavaScript can read a cookie containing an authentication token or session ID. If XSS occurs, an attacker can steal that value and impersonate the user.

Potential impact

  • Session hijacking
  • Authentication token disclosure
  • Account access combined with XSS

Remediation

  1. Set HttpOnly=true on sensitive cookies.
  2. Also apply Secure=true and an appropriate SameSite policy.
  3. Centralize cookie creation to enforce these security attributes by default.

Examples

Before

java
Cookie cookie = new Cookie("sid", token);
response.addCookie(cookie);

After

java
Cookie cookie = new Cookie("sid", token);
cookie.setHttpOnly(true);
cookie.setSecure(true);
response.addCookie(cookie);

The first example omits HttpOnly, allowing browser scripts to read the sensitive cookie. The second explicitly sets HttpOnly=true and also requires secure transport.

References