Headers Cookie Session Default

Consider changing the default session cookie name. An attacker can use it to fingerprint the server and target attacks accordingly.

IndexedPublic repositoryLowMedium confidenceVerifiedLGPL-3.0-onlyjavascript
greprules fetch gitlab-sast-rules-lgpl-javascript-headers-rule-cookie-session-default --engine opengrep

Description

Consider changing the default session cookie name. An attacker can use it to fingerprint the server and target attacks accordingly.

Detection target

Not provided

Recommended fix

Not provided

False-positive notes

Not provided

Community feedback

Sign in to report false positives, mark this rule useful, or suggest metadata improvements.