Vulnerability library
Security checkMay 13, 2024

Cookie Accessible for Subdomains

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Informational severityHTTP HeadersCookieData Security

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The presence of the Domain attribute in the Set-Cookie header instructs browsers to send the cookie to any subdomains of the specified domain. This can lead to unintended data exposure and potential security risks if sensitive information is stored in the cookie.

Recommendation

To limit cookie access to the current domain only, remove the Domain attribute from the Set-Cookie header. This ensures that the cookie is not accessible to subdomains, reducing the risk of data leakage.

References

Could your website be exposed too?

SmartScanner can check your website for Cookie Accessible for Subdomains and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 13, 2024