This page is experimental and may change significantly in future releases.
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Properties
id: d3f:CWE-614
- name
- Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
- definition
- The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.
Neighbors
CWE-614 has no direct neighbors in this release.Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-614 has no related weaknesses in this release.