Top 10 winner
Cookie Crumbles: Breaking and Fixing Web Session Integrity
Cookie Crumbles: Breaking and Fixing Web Session Integrity (Paper)
Studies cookie integrity across browsers and server frameworks and shows that the Secure attribute, cookie prefixes, SameSite and synchronizer CSRF tokens can be composed or implemented in ways that still allow session fixation and cross-origin request forgery. Nine of the top thirteen frameworks were affected, producing twelve CVEs and changes to the cookie standard.
Record
- Document
- Cookie Crumbles: Breaking and Fixing Web Session Integrity (Paper)
- Researcher
- Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei
- Published by
- USENIX Association
- Date
- Format
- Whitepaper
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .