Rust

Rust

Made by DeepSource

Audit required: Sensitive cookie without secure attribute RS-A1002

Security
Critical
a02 cwe-614 cwe-315 cwe-314 owasp top 10

Cookies set without the secure flag can cause the user agent to send those cookies in plaintext over an HTTP session with the same server. This can lead to man-in-the-middle attacks.

In past it has led to the following vulnerabilities:

Generally, the production sites redirect any requests that are sent over HTTP to the same URL but on HTTPS. In this case, make sure that these HTTP requests that are immediately redirected to HTTPS do not carry any cookie that contains sensitive information. The secure flag limits cookies to HTTPS traffic only so, the browser will never send secure cookies with requests that are not encrypted.

Bad practice

use cookie::Cookie;

let mut c = Cookie::new("data", "sensitive value")
c.set_secure(false);

Recommended

use cookie::Cookie;

let mut c = Cookie::new("data", "sensitive value")
c.set_secure(true);

References

Exceptions

While this issue mostly makes sense if you're setting a sensitive cookie, DeepSource will flag all the cookies encountered without the secure flag. This is to ensure that every cookie is audited carefully.