-
Type:
Bug
-
Status:
In Development
-
Priority:
Low
-
Resolution:
Unresolved
-
Affects Version/s:
None
-
Fix Version/s:
None
-
Component/s:
None
-
-
-
-
-
Module:
BenAdmin
- Security
-
-
Company:
All Clients/Multiple Clients
-
Item State:
Development
- In Analysis
A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.
For more details please refer attached HTML report
CC SamirRakesh RoyJaideep Vinchurkaranirudha joshi
SearchEmp_Spider.html
- relates to
-
NF-2714
Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.
-
-
To Do
{"report":{"apdex":1,"isInitial":true,"journeyId":"ef1073a2-45b2-461e-8b18-d33605b39e32","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":973.6999998092651,"redirectCount":0,"resourceLoadedEnd":758.6999998092651,"resourceLoadedStart":366.19999980926514,"resourceTiming":[{"duration":62.40000009536743,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":366.19999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":366.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":428.59999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":62.59999990463257,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":366.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":366.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":429.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":63.30000019073486,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":366.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":366.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":430,"responseStart":0,"secureConnectionStart":0},{"duration":63.69999980926514,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":366.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":366.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":430.59999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":64.5,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":367,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":367,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":431.5,"responseStart":0,"secureConnectionStart":0},{"duration":224.7000002861023,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":367.19999980926514,"connectEnd":367.19999980926514,"connectStart":367.19999980926514,"domainLookupEnd":367.19999980926514,"domainLookupStart":367.19999980926514,"fetchStart":367.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":434.09999990463257,"responseEnd":591.9000000953674,"responseStart":473.90000009536743,"secureConnectionStart":367.19999980926514},{"duration":354,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":367.80000019073486,"connectEnd":367.80000019073486,"connectStart":367.80000019073486,"domainLookupEnd":367.80000019073486,"domainLookupStart":367.80000019073486,"fetchStart":367.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":434.90000009536743,"responseEnd":721.8000001907349,"responseStart":526,"secureConnectionStart":367.80000019073486},{"duration":160,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":367.90000009536743,"connectEnd":367.90000009536743,"connectStart":367.90000009536743,"domainLookupEnd":367.90000009536743,"domainLookupStart":367.90000009536743,"fetchStart":367.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":436.09999990463257,"responseEnd":527.9000000953674,"responseStart":527.3000001907349,"secureConnectionStart":367.90000009536743},{"duration":160.40000009536743,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":368.09999990463257,"connectEnd":368.09999990463257,"connectStart":368.09999990463257,"domainLookupEnd":368.09999990463257,"domainLookupStart":368.09999990463257,"fetchStart":368.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":437.59999990463257,"responseEnd":528.5,"responseStart":528,"secureConnectionStart":368.09999990463257},{"duration":160.90000009536743,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":368.19999980926514,"connectEnd":368.19999980926514,"connectStart":368.19999980926514,"domainLookupEnd":368.19999980926514,"domainLookupStart":368.19999980926514,"fetchStart":368.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":438.90000009536743,"responseEnd":529.0999999046326,"responseStart":528.5999999046326,"secureConnectionStart":368.19999980926514},{"duration":161.2999997138977,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":368.30000019073486,"connectEnd":368.30000019073486,"connectStart":368.30000019073486,"domainLookupEnd":368.30000019073486,"domainLookupStart":368.30000019073486,"fetchStart":368.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":439.40000009536743,"responseEnd":529.5999999046326,"responseStart":529.1999998092651,"secureConnectionStart":368.30000019073486},{"duration":161.89999961853027,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":368.30000019073486,"connectEnd":368.30000019073486,"connectStart":368.30000019073486,"domainLookupEnd":368.30000019073486,"domainLookupStart":368.30000019073486,"fetchStart":368.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":439.90000009536743,"responseEnd":530.1999998092651,"responseStart":529.6999998092651,"secureConnectionStart":368.30000019073486},{"duration":71.40000009536743,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":368.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":368.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":439.80000019073486,"responseStart":0,"secureConnectionStart":0},{"duration":72.5,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":368.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":368.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":441.09999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":162.09999990463257,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/81da1c7492d7ee698ae1cc31902498d9/shortcuts.js?context=issuenavigation&context=issueaction","startTime":368.59999990463257,"connectEnd":368.59999990463257,"connectStart":368.59999990463257,"domainLookupEnd":368.59999990463257,"domainLookupStart":368.59999990463257,"fetchStart":368.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":442.40000009536743,"responseEnd":530.6999998092651,"responseStart":530.1999998092651,"secureConnectionStart":368.59999990463257},{"duration":165.90000009536743,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":368.69999980926514,"connectEnd":368.69999980926514,"connectStart":368.69999980926514,"domainLookupEnd":368.69999980926514,"domainLookupStart":368.69999980926514,"fetchStart":368.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":443.69999980926514,"responseEnd":534.5999999046326,"responseStart":530.8000001907349,"secureConnectionStart":368.69999980926514},{"duration":365.69999980926514,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":392.40000009536743,"connectEnd":392.40000009536743,"connectStart":392.40000009536743,"domainLookupEnd":392.40000009536743,"domainLookupStart":392.40000009536743,"fetchStart":392.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":563.0999999046326,"responseEnd":758.0999999046326,"responseStart":757.5999999046326,"secureConnectionStart":392.40000009536743},{"duration":366.2999997138977,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":392.40000009536743,"connectEnd":392.40000009536743,"connectStart":392.40000009536743,"domainLookupEnd":392.40000009536743,"domainLookupStart":392.40000009536743,"fetchStart":392.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":563.1999998092651,"responseEnd":758.6999998092651,"responseStart":758.1999998092651,"secureConnectionStart":392.40000009536743},{"duration":89.5,"initiatorType":"xmlhttprequest","name":"https://jira.workterra.net/rest/webResources/1.0/resources","startTime":735.0999999046326,"connectEnd":735.0999999046326,"connectStart":735.0999999046326,"domainLookupEnd":735.0999999046326,"domainLookupStart":735.0999999046326,"fetchStart":735.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":782.9000000953674,"responseEnd":824.5999999046326,"responseStart":823.8000001907349,"secureConnectionStart":735.0999999046326}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":226,"responseStart":337,"responseEnd":391,"domLoading":341,"domInteractive":1027,"domContentLoadedEventStart":1027,"domContentLoadedEventEnd":1083,"domComplete":1377,"loadEventStart":1377,"loadEventEnd":1379,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[],"measures":[],"correlationId":"5418b51cdd5fff","effectiveType":"4g","downlink":9.3,"rtt":0,"serverDuration":93,"dbReadsTimeInMs":30,"dbConnsTimeInMs":35,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}
Yes, we need to take care of this. While development we need to handle this such way that, we should pass a cookie value from server side code to function in java script code , so that after making 'IdForLoginValidation' cookie as HTTPOnly, there will not be an issue while reading this cookie value in java script, as currently we are accessing this cookie inside WORKTERRALogin.js to check user session.