VariantDraft

CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Category: auth

Description

The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Common consequences· 1

  • Confidentiality — Read Application Data
    Omitting the secure flag makes it possible for the user agent to send the cookies in plaintext over an HTTP session.

Potential mitigations· 1

  • [Implementation]Always set the secure attribute when the cookie should be sent via HTTPS only.

Related CAPEC attack patterns· 1

CAPEC-102

References

  1. https://cwe.mitre.org/data/definitions/614.html

Exploits (incoming)1

TypeTargetConfidenceTier
AttackPatternSession Sidejackingcapec-102100%live

(incoming)2

TypeTargetConfidenceTier
VulnerabilityCVE-2025-24897cve-2025-248970%live
VulnerabilityCVE-2025-8037cve-2025-80370%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Sensitive Cookie with Improper SameSite Attribute
CWE
Sensitive Cookie Without 'HttpOnly' Flag
CWE
Use of HTTP Request With Sensitive Query String
CWE
Session Fixation
CWE
Use of Persistent Cookies Containing Sensitive Information
CWE
Cross-Site Request Forgery (CSRF)
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.