Description
Cookies containing authentication tokens, session identifiers, or API keys may be sent over non-HTTPS connections if they lack the Secure flag. A network attacker may steal them from plaintext HTTP requests or downgraded paths and attempt session hijacking or an authentication bypass.
Potential impact
- A man-in-the-middle attacker may capture session cookies or tokens from plaintext HTTP requests.
- Stolen cookies may allow impersonation of a user session or access to privileged APIs.
- Even an HTTPS site may expose cookies through some HTTP paths or redirects.
Remediation
- Set
secure: trueon sensitive server cookies. - Also use
HttpOnlyandSameSiteto reduce script access and CSRF risk. - When constructing
Set-Cookieheaders directly, includeSecureand allow transport only over HTTPS.
Examples
Before
javascript
app.post("/login", (req, res) => {
const token = createSession(req.user);
res.cookie("session", token, { httpOnly: true });
res.send("ok");
});
After
javascript
app.post("/login", (req, res) => {
const token = createSession(req.user);
res.cookie("session", token, {
secure: true,
httpOnly: true,
sameSite: "Lax",
});
res.send("ok");
});
Explanation:
- Before: The sensitive session cookie lacks
Secureand may be sent over HTTP. - After:
Secure,HttpOnly, andSameSiterestrict transmission and access.