Missing Secure Flag on the SSL Cookie after a vulnerability assessment ran on PA820

cancel
Showing results for 
Search instead for 
Did you mean: 

Missing Secure Flag on the SSL Cookie after a vulnerability assessment ran on PA820

L4 Transporter

In my case, the team is performing a vulnerability assessment on PA820

Vulnerability Title: Missing Secure Flag From SSL Cookie 

Description: The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the application can be accessed over both HTTP and HTTPS, then there is the potential that the cookie can be sent in cleartext.

 

The scanning was running to the MGMT IP,

 

How to find out the Missing Secure Flag on the SSL Cookie

1 REPLY 1

Community Team Member

Hi @Mohammed_Yasin ,

 

https://live.paloaltonetworks.com/t5/threat-vulnerability-discussions/check-and-help-resolving-vapt-...

 

I'd recommend reaching out to support with the findings of your vulnerability assessment.

 

Cheers,

-Kiwi.

 
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!