9 vulnerabilities classified as CWE-1275. AI Chinese analysis included.
CWE-1275 represents a configuration weakness where sensitive cookies lack a proper SameSite attribute or utilize an insecure value like 'None'. This flaw typically enables Cross-Site Request Forgery (CSRF) attacks, as browsers automatically attach these cookies to cross-domain POST requests initiated by malicious third-party sites. Without strict SameSite restrictions, attackers can exploit authenticated sessions to perform unauthorized actions on behalf of victims. To mitigate this risk, developers must explicitly set the SameSite attribute to 'Strict' or 'Lax' for all sensitive cookies, ensuring they are only sent in first-party contexts. Additionally, implementing the 'Secure' flag guarantees transmission over HTTPS, while robust input validation and anti-CSRF tokens provide layered defense against session hijacking and unauthorized state changes.
let sessionId = generateSessionId() let cookieOptions = { domain: 'example.com' } response.cookie('sessionid', sessionId, cookieOptions)
<html> <form id=evil action="http://local:3002/setEmail" method="POST"> <input type="hidden" name="newEmail" value="abc@example.com" /> </form> <script>evil.submit()</script> </html>
Vulnerabilities classified as CWE-1275 represent 9 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.