Sensitive cookies without the Secure flag

Sensitive cookies without the Secure flag

Description

Cookies containing authentication tokens, session identifiers, or API keys may be sent over non-HTTPS connections if they lack the Secure flag. A network attacker may steal them from plaintext HTTP requests or downgraded paths and attempt session hijacking or an authentication bypass.

Potential impact

  • A man-in-the-middle attacker may capture session cookies or tokens from plaintext HTTP requests.
  • Stolen cookies may allow impersonation of a user session or access to privileged APIs.
  • Even an HTTPS site may expose cookies through some HTTP paths or redirects.

Remediation

  • Set secure: true on sensitive server cookies.
  • Also use HttpOnly and SameSite to reduce script access and CSRF risk.
  • When constructing Set-Cookie headers directly, include Secure and allow transport only over HTTPS.

Examples

Before

javascript
app.post("/login", (req, res) => {
  const token = createSession(req.user);
  res.cookie("session", token, { httpOnly: true });
  res.send("ok");
});

After

javascript
app.post("/login", (req, res) => {
  const token = createSession(req.user);
  res.cookie("session", token, {
    secure: true,
    httpOnly: true,
    sameSite: "Lax",
  });
  res.send("ok");
});

Explanation:

  • Before: The sensitive session cookie lacks Secure and may be sent over HTTP.
  • After: Secure, HttpOnly, and SameSite restrict transmission and access.

References