Hello team,
Our penetration testing team report and issue stating ajs_anonymous_id and ajs_group_id are insecure cookies:
Below is the issue:
Cookies are used mostly to achieve the below
1. Session Management
2. Tracking
To secure the cookies and reduce the attack surface surrounding the cookies, attributes were introduced which are discussed below
1. Secure: This attribute tells the browser to only send the cookies over a secure HTTPS connection.
2. HttpOnly: This attribute prevents cookies from being accessed from the client-side Javascript.
3. Expires: This attribute helps the application to set persistent cookies.
4. SameSite: This attribute is used to prevent browsers from using cookies for cross-origin requests.
After investigation we notices that its from jsd. Could you please confirm that are these insecure if yes we need to remove the jsd.
Thanks,
Yougal BISHT
Securends