oss-sec mailing list archives

Re: Re: Question regarding CVE applicability of missing HttpOnly flag


From: Florian Weimer <fweimer () redhat com>
Date: Thu, 26 Jun 2014 09:50:53 +0200

On 06/26/2014 01:07 AM, cve-assign () mitre org wrote:
   -- compared to the development cost in arranging for the flag to be
      set, is it possible that the real-life benefit is too small?

You need a separate vulnerability to access the cookie. These vulnerabilities will have to be addressed even if the HttpOnly flag is set because indirectly, they usually give attackers access to information from which cookies are derived (e.g., by injecting a malicious login form). Therefore, I think the HttpOnly flag is just hardening, and it's not even a very effective form of it.

--
Florian Weimer / Red Hat Product Security


Current thread: