Post by JNeuhoff » Mon Aug 16, 2021 10:08 pm

A recent PCI scan for one of our live sites, based on OpenCart 3.0.2.0, resulted in this fail message with regards to PCI compliancy:

Insecure configuration of Cookie attributes
URL: https://www.megahome-distillers.co.uk/i ... /cart/edit
Port: tcp/443

Has anybody got a solution for this issue?

Looking at the developer's console, the website already uses secure http-only OCSESSID, hence my above question.

Attachments

Screenshot_2021-08-16_15-02-11.png

developer console - Screenshot_2021-08-16_15-02-11.png (85.67 KiB) Viewed 1811 times


Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig


User avatar
Guru Member

Posts

Joined
Wed Dec 05, 2007 3:38 am


Post by ADD Creative » Mon Aug 16, 2021 10:49 pm

Could it be the issue of the OCSESSID being set twice in every response that is confusing the scanner?

www.add-creative.co.uk


Expert Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by JNeuhoff » Tue Aug 17, 2021 12:41 am

It does indeed set it twice, e.g.

system/framework.php: setcookie('OCSESSID', 'xxxxxxxxxxxxxxxxxxx', '0', '/', '',true,true)'
catalog/controller/startup/session.php: setcookie('OCSESSID', 'xxxxxxxxxxxxxxxxxxx', '0', '/', '',true,true)'

However, the response header only comes back with one OCSESSID, and its value isn't changed!

Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig


User avatar
Guru Member

Posts

Joined
Wed Dec 05, 2007 3:38 am

Who is online

Users browsing this forum: No registered users and 101 guests