You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Learn more on MITRE.
Impact
Setting
$secure
or$httponly
value totrue
inConfig\Cookie
is not reflected inset_cookie()
orResponse::setCookie()
.The following code does not issue a cookie with the secure flag even if you set
$secure = true
inConfig\Cookie
.Patches
Upgrade to v4.2.7 or later.
Workarounds
References
For more information
If you have any questions or comments about this advisory: