Skip to content

Need a new VRT entry for session token transferred over unencrypted channel (for non-cookie headers) #153

Description

@TheGarth

Right now we have an entry for "Server Security Misconfiguration" > "Missing Secure or HTTPOnly Cookie Flag" > "Session Token", at a P4. But (from what I can tell), we do not have anything equivalent for tokens submitted via other headers, and the previously mentioned VRT does not seem like an appropriate fit.

I propose something along the lines of a "Server Security Misconfiguration" > "Session Token Transferred Over Unencrypted Channel", at a default P4.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions