Re: [webmin-l] Security scan result: Missing `httpOnly` Cookie Attribute and Missing `secure` Cookie Attribute

Andrey Repin <[email protected]>
Newsgroups gmane.comp.web.webmin.general
Message-ID <[email protected]>
Greetings, Clement Ogedengbe!

>  The flaw is due to a cookie is not using the 'httpOnly' attribute. This
> allows a cookie to be accessed by JavaScript which could lead to session
> hijacking attacks.

Only if you have installed an untrusted javascript on your webmin host.

> Can someone please help with any idea about how to fix this:

Working as intended, nothing to fix.


-- 
With best regards,
Andrey Repin
Thursday, March 14, 2019 4:07:53

Sorry for my terrible english...



-
Forwarded by the Webmin mailing list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.