Sensitive Cookie Without 'HttpOnly' Flag in kasuganosoras/pigeonValid
Oct 24th 2021
One or more cookies don't have the HttpOnly flag set. When a cookie is set with the HttpOnly flag, it instructs the browser that the cookie can only be accessed by the server and not by client-side scripts. This is an important security protection for session cookies.
If possible, you should set the HttpOnly flag for these cookies.