The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

cookie without secure flag - different issues

Robin | Last updated: Mar 20, 2017 10:26AM UTC

Can you explain the difference in these two issue which have both been flagged on the same site? Issue:  SSL cookie without secure flag set Severity:  Medium Confidence:  Firm Host:  https://abc Path:  / Set-Cookie: ASP.NET_SessionId=054nklywi05mesavwtc3g4ck; path=/; HttpOnly Issue:  SSL cookie without secure flag set Severity:  Information Confidence:  Certain Host:  https://abc Path:  /login.aspx Set-Cookie: .ASPXAUTH=686...3E29CB0; path=/; HttpOnly They are both from different pages but both for cookies which obviously don't have the secure flag. Why is one Informational and one Medium? And what is the difference between Firm and Certain? It doesn't really make a difference in this instance but if there are other findings which are sometimes logged as info and sometimes as more serious then it might trip some people up.

PortSwigger Agent | Last updated: Mar 20, 2017 11:42AM UTC