• Hi @AYadav647471 (Community Member)​,

     

    One of the reasons Veracode Dynamic Analysis reports CWE 402 is the lack of the `httponly` flag on a cookie. The concern here would mainly be about the confidentiality of cookie values if the application has an XSS vulnerability where an attacker can execute malicious JavaScript in the web browser of a victim. In such a scenario, an attacker can read the values of any cookie that doesn't have `httponly` set, and potentially read security-sensitive values, such as session tokens.

     

    If you want more specific guidance, please provide a bit more context.

     

    Thank you,

    Florian Walter

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.