Cookie Security
What Barrion checks when it evaluates the security attributes on your site's cookies.
Barrion checks whether the cookies your site sets are configured with the security attributes needed to protect them from theft and misuse. Cookies are commonly used to store session tokens, the keys that keep users logged in, so their security is critical.
What Barrion Checks
Cookie Security Attributes
Barrion inspects every Set-Cookie header returned by your server and checks for three attributes:
Secure: Without this flag, the cookie is sent over both encrypted (HTTPS) and plain (HTTP) connections. On an unencrypted connection, attackers can intercept the cookie and use it to impersonate the user.
HttpOnly: Without this flag, JavaScript on the page can read the cookie's value. If an attacker manages to inject script into your page, they can steal the cookie and gain access to the user's account.
SameSite: Without this flag, the browser sends the cookie with requests that originate from other websites. This can allow malicious sites to trigger authenticated actions on your application using a victim's active session.
Severity: High
What to Do
Cookie attributes are set in your application code or web framework configuration. Share this finding with your development team. Most frameworks provide session configuration options that apply these attributes globally, making it a straightforward fix. Barrion lists the specific cookies that are missing attributes in the finding details.