CWE-539: Information Leak Through Persistent Cookies
Information Leak Through Persistent Cookies
Weakness ID: 539 (Weakness Variant)
Status: Incomplete
Description
Description Summary
Persistent cookies are cookies that are stored on the browser's
hard drive. This can cause security and privacy issues depending on the
information stored in the cookie and how it is accessed.
Time of Introduction
Architecture and Design
Implementation
Potential Mitigations
Phase
Description
Do not store sensitive information in persistent cookies.
Other Notes
Cookies are small bits of data that are sent by the web application but
stored locally in the browser. This lets the application use the cookie to
pass information between pages and store variable information. The web
application controls what information is stored in a cookie and how it is
used. Typical types of information stored in cookies are session
Identifiers, personalization and customization information, and in rare
cases even usernames to enable automated logins. There are two different
types of cookies: session cookies and persistent cookies. Session cookies
just live in the browser's memory, and are not stored anywhere, but
persistent cookies are stored on the browser's hard drive.