Permissive HTTP Only option in cookie configuration


Leaving the HTTP Only option in cookie configuration unset or false can expose your application to attacks by allowing client-side scripts to access cookie values. This vulnerability can lead to unauthorized access or exploits.


  • Do set HttpOnly to true for cookies to prevent client-side scripts from accessing the cookie values. This step is crucial for enhancing the security of your application by limiting access to cookie data.

Associated CWE

OWASP Top 10


To skip this rule during a scan, use the following flag

bearer scan /path/to/your-project/ --skip-rule=java_lang_cookie_with_http_only_false

To run only this rule during a scan, use the following flag

bearer scan /path/to/your-project/ --only-rule=java_lang_cookie_with_http_only_false