-
Aug 8th, 2012, 11:05 PM
#1
httpOnly on Context
Hello,
I am running compliance check on my web application and there was a vulnerability saying cookie doesn't contain httpOnly. I am using tomcat 7.0.27. I assume from the posts that tomcat 7+ by default have this flag as true.
I have also explicitly set it on my context as true. I have also set the session-config / cookie-config as secure.
But still I get the same vulnerability. I am confused.
Can someone help me out please?
Thanks & Regards
Surya
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules