<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI Compliance Failure in APIs &amp; Integrations</title>
    <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/989649#M74196</link>
    <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;setting "Use secure cookies only" fix "secure" attribute for&amp;nbsp;&lt;SPAN&gt;JSESSIONID&lt;/SPAN&gt; cookie. But it doesn't fix HTTPOnly attribute&lt;SPAN&gt;. Is there a plan to fix this as well?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2024 10:29:24 GMT</pubDate>
    <dc:creator>TNail</dc:creator>
    <dc:date>2024-06-10T10:29:24Z</dc:date>
    <item>
      <title>PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/378094#M37171</link>
      <description>&lt;P&gt;Recently my website has started to fail PCI Compliance scans through Trustwave. Part of it is related to Hub Spot cookies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DetectionDetails: Cookie Vulnerabilities Found __hssrc=1 Path = / Host = 0.0.0.0 Cookie does not have secure attribue in HTTPS Cookie does not have an HTTPOnly Attribute Cookie Change Observed on CLIENTside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We've migrated to the external merchant forms so we no longer need to worry about the PCI scan here, but I wanted to pass this along so Hubspot was aware. I'm not sure if the secure attribute can be set on the HS cookies, but might want to look into it. There were also other non-session cookies flagged in the scan to with other frameworks we used, so I don't know if its really a problem with them, or more of a problem with Trustwave's automated session cookie detection.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 15:34:37 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/378094#M37171</guid>
      <dc:creator>joseph_costello</dc:creator>
      <dc:date>2020-10-12T15:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/378127#M37175</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/148078"&gt;@joseph_costello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for flagging!&amp;nbsp; I Will get this to the team to check it out&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 17:51:43 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/378127#M37175</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2020-10-12T17:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425557#M42282</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any developments on that front? We'd also need the cookies to be HttpOnly for security reasons.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 15:25:41 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425557#M42282</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-04-07T15:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425593#M42289</link>
      <description>&lt;P&gt;@Anonymous&lt;/a&gt; , yep there has been development.&amp;nbsp; It is an alpha form and will be released as an in app feature.&lt;/P&gt;
&lt;P&gt;I have a reminder set to check in on this later this month &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; but please feel free to yell at me if I am not responsive.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 16:19:18 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425593#M42289</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-04-07T16:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425597#M42290</link>
      <description>&lt;P&gt;Awesome, thanks for the quick response. Looking forward to that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 16:24:58 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/425597#M42290</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-04-07T16:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/462452#M45180</link>
      <description>&lt;P&gt;Any update on this? As this is needed for the same above reasons.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 08:28:25 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/462452#M45180</guid>
      <dc:creator>KT17</dc:creator>
      <dc:date>2021-07-20T08:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/471414#M45556</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;!&lt;BR /&gt;&lt;BR /&gt;Are there any updates?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 10:02:02 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/471414#M45556</guid>
      <dc:creator>kate4</dc:creator>
      <dc:date>2021-08-03T10:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/471794#M45573</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/118421"&gt;@kate4&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Glad you asked &lt;span class="lia-unicode-emoji" title=":winking_face_with_tongue:"&gt;😜&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you go &lt;A href="https://app.hubspot.com/l/settings/analytics-and-tracking/domains" target="_blank" rel="noopener"&gt;here,&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;you should be able to now select "Use secure cookies only"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Settings.png" style="width: 999px;"&gt;&lt;img src="https://community.hubspot.com/t5/image/serverpage/image-id/47491i91AFED3DC4018FE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Settings.png" alt="Settings.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 18:53:49 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/471794#M45573</guid>
      <dc:creator>dennisedson</dc:creator>
      <dc:date>2021-08-03T18:53:49Z</dc:date>
    </item>
    <item>
      <title>"HTTP Only" security issue with hubspot code</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/554400#M50042</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found the following security issue from WANS scan report&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Threat&lt;/STRONG&gt;&lt;BR /&gt;The cookie does not contain the "HTTPOnly" attribute.&lt;BR /&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Cookies without the "HTTPOnly" attribute are permitted to be accessed via JavaScript. Cross-site scripting attacks can steal cookies which could lead to user&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;impersonation or compromise of the application account.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;BR /&gt;If the associated risk of a compromised account is high, apply the "HTTPOnly" attribute to cookies.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Detection Information&lt;BR /&gt;Cookie Name(s)&amp;nbsp; messagesUtk, __hssc, __hssrc, __hstc, hubspotutk&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 22:45:01 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/554400#M50042</guid>
      <dc:creator>PPointPredict</dc:creator>
      <dc:date>2022-01-11T22:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/989649#M74196</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;setting "Use secure cookies only" fix "secure" attribute for&amp;nbsp;&lt;SPAN&gt;JSESSIONID&lt;/SPAN&gt; cookie. But it doesn't fix HTTPOnly attribute&lt;SPAN&gt;. Is there a plan to fix this as well?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:29:24 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/989649#M74196</guid>
      <dc:creator>TNail</dc:creator>
      <dc:date>2024-06-10T10:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1221520#M85311</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;, is there any update on this?&amp;nbsp; Maybe a work-around?&amp;nbsp; It's 2025 and my vulnerability scans are now failing do to the lack of&amp;nbsp;&lt;SPAN&gt;HttpOnly.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 17:18:07 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1221520#M85311</guid>
      <dc:creator>CDavis45</dc:creator>
      <dc:date>2025-11-07T17:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1254589#M86970</link>
      <description>&lt;P&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&amp;nbsp;Is there any update on this? It's 2026 now and my vulnerability scans still fail. I have enabled "Use secure cookies only" a long time ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 16:02:27 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1254589#M86970</guid>
      <dc:creator>BGarcia09</dc:creator>
      <dc:date>2026-02-27T16:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance Failure</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1256414#M87062</link>
      <description>&lt;P&gt;Hey &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/1008580"&gt;@BGarcia09&lt;/a&gt;&lt;/SPAN&gt; - thanks for following up here!&lt;BR /&gt;&lt;BR /&gt;Aside from re-tagging &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/13982"&gt;@dennisedson&lt;/a&gt;&lt;/SPAN&gt;, I'd also like to tag in &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/537570"&gt;@RubenBurdin&lt;/a&gt;&lt;/SPAN&gt; and &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/283867"&gt;@EValdes&lt;/a&gt;&lt;/SPAN&gt; to see if either of them have any insight on there being any update regarding this.&lt;BR /&gt;&lt;BR /&gt;Shane, Senior Community Moderator&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 19:12:32 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/PCI-Compliance-Failure/m-p/1256414#M87062</guid>
      <dc:creator>STierney</dc:creator>
      <dc:date>2026-03-05T19:12:32Z</dc:date>
    </item>
  </channel>
</rss>

