Insecure cookies

Overview

The <isSecure> attribute controls whether a cookie can only be accessed through HTTPS or not. By setting this attribute to false, sensitive cookies may be exposed if sent over an insecure connection.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Rare

Incidence

How common is this issue?
2%0%
arrow down1%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
4 years3 months
arrow down92%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconUse of Encryptionicon