Right now we have an entry for "Server Security Misconfiguration" > "Missing Secure or HTTPOnly Cookie Flag" > "Session Token", at a P4. But (from what I can tell), we do not have anything equivalent for tokens submitted via other headers, and the previously mentioned VRT does not seem like an appropriate fit.
I propose something along the lines of a "Server Security Misconfiguration" > "Session Token Transferred Over Unencrypted Channel", at a default P4.
Right now we have an entry for "Server Security Misconfiguration" > "Missing Secure or HTTPOnly Cookie Flag" > "Session Token", at a P4. But (from what I can tell), we do not have anything equivalent for tokens submitted via other headers, and the previously mentioned VRT does not seem like an appropriate fit.
I propose something along the lines of a "Server Security Misconfiguration" > "Session Token Transferred Over Unencrypted Channel", at a default P4.