httpOnly issue
Hello, all,
Where I work, we have to adhere to a very strict set of security protocols. It makes my job difficult, most of the time. More so than any other job I've ever worked.
We have to follow STIG guidelines, typically 300-400 pages of instructions. One of these guidelines states that we have to use httpOnly in our application.cfc/cfm files. We also set that in the web.xml file, so it should apply to all projects running under CF.
However, we have been informed by our security experts that there is a finding. While they do see that we are using httpOnly, they claim that all of the session cookies have the httpOnly flag set, one of them is missing the secure flag. No mention of which one.
What am I missing, here?
V/r,
^ _ ^
