Skip to content
Discussion options

You must be logged in to vote

But this isn't a secure problem? I tested the secure of a laravel application and i had the following problem:

This is a False Positive and can be safely ignored. This cookie is intentionally set without httponly because it is required by the javascript to work.

Automated security scanners are ignorant of implementation details like this, so although they work really well for finding low-hanging fruit, they also find things that look like security risks, but really aren't.
I'm a penetration tester, so I'm always seeing this popup in scanners and I advise my clients to ignore it.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@valorin
Comment options

@JoaVitoTavares
Comment options

@henzeb
Comment options

@valorin
Comment options

Answer selected by JoaVitoTavares
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants