Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-12637

[Security] ZAP Scan Issue : Cookie No HttpOnly Flag

    Details

    • Type: Bug
    • Status: In Development
    • Priority: Low
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Production
    • Bug Severity:
      Low
    • Level:
      Admin, Employee, Partner
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - In Analysis

      Description

      A cookie has been set without the HttpOnly flag, which means that the cookie can be accessed by JavaScript. If a malicious script can be run on this page then the cookie will be accessible and can be transmitted to another site. If this is a session cookie then session hijacking may be possible.

      For more details please refer attached HTML report

      CC SamirRakesh RoyJaideep Vinchurkaranirudha joshi
      SearchEmp_Spider.html

        Attachments

          Issue Links

            Activity

            prasadp Prasad Pise (Inactive) created issue -
            prasadp Prasad Pise (Inactive) made changes -
            Field Original Value New Value
            Link This issue relates to NF-2714 [ NF-2714 ]
            prasadp Prasad Pise (Inactive) made changes -
            Attachment StaticReport_Spider.html [ 69272 ]
            prasadp Prasad Pise (Inactive) made changes -
            Attachment EnrollNowWithPartnerLogin.html [ 69273 ]
            santosh.balid Santosh Balid (Inactive) made changes -
            Status Open [ 1 ] In Development [ 10007 ]
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Yes, we need to take care of this. While development we need to handle this such way that, we should pass a cookie value from server side code to function in java script code , so that after making 'IdForLoginValidation' cookie as HTTPOnly, there will not be an issue while reading this cookie value in java script, as currently we are accessing this cookie inside WORKTERRALogin.js to check user session.

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Yes, we need to take care of this. While development we need to handle this such way that, we should pass a cookie value from server side code to function in java script code , so that after making 'IdForLoginValidation' cookie as HTTPOnly, there will not be an issue while reading this cookie value in java script, as currently we are accessing this cookie inside WORKTERRALogin.js to check user session.
            santosh.balid Santosh Balid (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: On Hold(10207)
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            This Will be on-hold till we do not plan it for development in upcoming sprint.

            Cc: Jaideep Vinchurkar

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - This Will be on-hold till we do not plan it for development in upcoming sprint. Cc: Jaideep Vinchurkar
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Please plan it in future sprints.

            Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute
            santosh.balid Santosh Balid (Inactive) made changes -
            Assignee Santosh Balid [ santosh.balid ] Gaurav Sodani [ gaurav.sodani ]
            santosh.balid Santosh Balid (Inactive) logged work - 28/Feb/18 02:11 PM
            • Time Spent:
              3.5h
               
              <No comment>
            santosh.balid Santosh Balid (Inactive) made changes -
            Remaining Estimate 0h [ 0 ]
            Time Spent 3.5h [ 12600 ]
            Worklog Id 106728 [ 106728 ]
            santosh.balid Santosh Balid (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: On Hold(10207) Parent values: Development(10200)Level 1 values: In Analysis(10204)
            santosh.balid Santosh Balid (Inactive) logged work - 01/Mar/18 01:27 PM
            • Time Spent:
              4h
               
              <No comment>
            santosh.balid Santosh Balid (Inactive) made changes -
            Time Spent 3.5h [ 12600 ] 7.5h [ 27000 ]
            Worklog Id 107676 [ 107676 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Gaurav Sodani [ gaurav.sodani ] Vijayendra Shinde [ ID10506 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to DEV-13718 [ DEV-13718 ]
            Transition Time In Source Status Execution Times
            Santosh Balid (Inactive) made transition -
            Open In Development
            6d 5h 27m 1

              People

              Assignee:
              vijayendra Vijayendra Shinde (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 7.5h
                  7.5h