Sensitive Cookie with Improper SameSite Attribute
CWE-1275 · Variant · Incomplete
The SameSite attribute for sensitive cookies is not set, or an insecure value is used.
Extended description
The SameSite attribute controls how cookies are sent for cross-domain requests. This attribute may have three values: 'Lax', 'Strict', or 'None'. If the 'None' value is used, a website may create a cross-domain POST HTTP request to another website, and the browser automatically adds cookies to this request.
This may lead to Cross-Site-Request-Forgery (CSRF) attacks if there are no additional protections in place (such as Anti-CSRF tokens).