Ad Widget

Collapse

Missing httpOnly Cookie Attribute

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • mururoa
    Junior Member
    • Jul 2014
    • 11

    #1

    Missing httpOnly Cookie Attribute

    Scanning vulnerabilities I found the 'Missing httpOnly Cookie Attribute' with zabbix (3.2).
    I know, this is an old zabbix problem not solved yet in the code.
    I tried different ways to fix that directly in nginx with no luck.

    What we have is : Set-Cookie: zbx_sessionid=a1be95629e8ad884ac1f498f817ccc6a; secure

    And what we should have (as far I understand) is : Set-Cookie: zbx_sessionid=a1be95629e8ad884ac1f498f817ccc6a; secure ; HttpOnly

    Somebody already fixed that one way or another ?
    Last edited by mururoa; 29-11-2016, 22:54.
  • sbrews
    Junior Member
    • Dec 2016
    • 10

    #2
    httponly

    Seeing as the parent post was done in November and there have been no replies, should one assume that httponly is not yet supported in zabbix? Is there an ETA as to when it might be supported?

    Comment

    • mururoa
      Junior Member
      • Jul 2014
      • 11

      #3
      no replies

      No replies so far.
      Maybe someone may alert the developpers ?

      Comment

      Working...