Using default cookie configurations can expose your application to security risks. This vulnerability occurs when cookies are set with default values, making them predictable and easier for attackers to exploit.
Remediation Guidelines
Do not rely on default cookie names.
Do use generic, non-descriptive names for session cookies. This makes it harder for attackers to identify and exploit your application's session management mechanism.
Do always specify a maxAge or expires value to control the cookie's lifetime.