Skip to main content

V3.4 — Cookie-based Session Management

Cookie-based Session Management: 5 L3 requirement(s). V3.4.1: Verify that cookie-based session tokens have the 'Secure' attribute set. (C6) V3.4.2: Verify that cookie-based session tokens have the 'HttpOnly' attribute set. (C6) V3.4.3: Verify that cookie-based session tokens utilize the 'SameSite' attribute to limit exposure to cross-site request forgery... ... and 2 more.

PropertyValue
SectionV3.4
Ownerplatform

Mapped Controls

ControlTitle
SID-AUTH-02JWT Bearer Token Session Management

Source: OWASP Application Security Verification Standard 4.0.3