CWE
Home > CWE List > CWE-539 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-539 Individual Dictionary Definition (Draft 9)

Information Leak Through Persistent Cookies
Weakness ID
Status: Incomplete

539 (Weakness Variant)

Description

Summary

Persistent cookies are cookies that are stored on the browser's hard drive. This can cause security and privacy issues depending on the information stored in the cookie and how it is accessed.

Context Notes

Cookies are small bits of data that are sent by the web application but stored locally in the browser. This lets the application use the cookie to pass information between pages and store variable information. The web application controls what information is stored in a cookie and how it is used. Typical types of information stored in cookies are session Identifiers, personalization and customization information, and in rare cases even usernames to enable automated logins. There are two different types of cookies: session cookies and persistent cookies. Session cookies just live In the browser's memory, and are not stored anywhere, but persistent cookies are stored on the browser's hard drive.

Relationships
NatureTypeIDName
ChildOfWeakness ClassWeakness ClassWeakness Class538File and Directory Information Leaks
Source Taxonomies

Anonymous Tool Vendor (under NDA) -

Related Attack Patterns
CAPEC-IDAttack Pattern Name
21Exploitation of Session Variables, Resource IDs and other Trusted Credentials
39Manipulating Opaque Client-based Data Tokens
31Accessing/Intercepting/Modifying HTTP Cookies
60Reusing Session IDs (aka Session Replay)
59Session Credential Falsification through Prediction
Page Last Updated: April 22, 2008