Jira Software 7.0.11, RHEL 8, miniOrange SAML Single Sign-On plugin.
When my security team runs scans on the instance, it is finding the cookies below without a secure flag or httponly set. The JSESSIONID is correct, but the other three are not. I have attempted several changes to files in ../jira/conf/ without luck.
>POST /plugins/servlet/saml/auth HTTP/1.1 response cookies w/out secure flag or httponly set:
Set-Cookie: JSESSIONID=6E9D0ACB3A0C20D58353E84371CB6D5D; Path=/; Secure; HttpOnly
Set-Cookie: SESSIONCOOKIE=SessionCookie; Expires=Thu, 22-Mar-2018 19:45:31 GMT; Path=/
Set-Cookie: LOGOUTCOOKIE=fd240320-cae9-4dc2-b317-b9d5f68c02fa; Path=/
Set-Cookie: SAMLCOOKIE=v9cHZqt0krk6osPa+RfytKA1ZD238kt2VXb0Qqo786le523vH04FbajQjgquKA8m; Path=/