Missing Protection against Session Fixation Attacks
Overview
Description
Remediation Guidelines
http.sessionManagement().sessionFixation().none() // not recommendedhttp.sessionManagement().sessionFixation().newSession() // or http.sessionManagement().sessionFixation().migrateSession()
References
Configuration
PreviousMissing or Permissive SSL Hostname VerifierNextMissing Secure option in cookie configuration
Last updated