Forum Discussion
The cookie does not contain the "HTTPOnly" attribute.
Hi All, we got vulnerability as below in our vulnerability scan
Threat The cookie does not contain the "HTTPOnly" attribute.
Impact Cookies without the "HTTPOnly" attribute are permitted to be accessed via JavaScript. Cross-site scripting attacks can steal cookies which could lead to user impersonation or compromise of the application account.
Solution If the associated risk of a compromised account is high, apply the "HTTPOnly" attribute to cookies.
But We need both the HTTPOnly and Secure flags set on the cookies. can you please let me know if this can be achieved if i made the setting http only on the cookie ? or please suggest me if any thing else need to be taken care
- vvskaladhar_488Nimbostratus
Hi All,
As per my understanding "HTTPOnly" attribute to cookies can be inserted Only by using ASM as I dont see this option in LTM . please let me know if there is any way to solve above vulnerability.
- Maneesh_72711Cirrostratus
Check this one from Aaron. https://devcentral.f5.com/questions/cookie-persistence-sendfor-http-only
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com