• Live group demo of Marketing Hub + Data Agent

    Standardize reporting, reduce manual work, and introduce AI without cleanup

    Join us on March 12
  • Ready to build your local HubSpot community?

    HUG leaders host events, spark connections, and create spaces where people learn and grow together.

    Become a HUG Leader

PCI Compliance Failure

joseph_costello
Member

Recently my website has started to fail PCI Compliance scans through Trustwave. Part of it is related to Hub Spot cookies.

 

DetectionDetails: Cookie Vulnerabilities Found __hssrc=1 Path = / Host = 0.0.0.0 Cookie does not have secure attribue in HTTPS Cookie does not have an HTTPOnly Attribute Cookie Change Observed on CLIENTside

 

 

We've migrated to the external merchant forms so we no longer need to worry about the PCI scan here, but I wanted to pass this along so Hubspot was aware. I'm not sure if the secure attribute can be set on the HS cookies, but might want to look into it. There were also other non-session cookies flagged in the scan to with other frameworks we used, so I don't know if its really a problem with them, or more of a problem with Trustwave's automated session cookie detection. 

1 Accepted solution
dennisedson
Solution
Community Manager
Community Manager

@kate4 ,

Glad you asked 😜

If you go here,

you should be able to now select "Use secure cookies only"

Settings.png


loop Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.
Learn More

View solution in original post

12 Replies 12
PPointPredict
Member

Hi all,

 

We found the following security issue from WANS scan report

Threat
The cookie does not contain the "HTTPOnly" attribute.
Impact
Cookies without the "HTTPOnly" attribute are permitted to be accessed via JavaScript. Cross-site scripting attacks can steal cookies which could lead to user
impersonation or compromise of the application account. 
Solution
If the associated risk of a compromised account is high, apply the "HTTPOnly" attribute to cookies.


Detection Information
Cookie Name(s)  messagesUtk, __hssc, __hssrc, __hstc, hubspotutk

0 Upvotes
dennisedson
Solution
Community Manager
Community Manager

@kate4 ,

Glad you asked 😜

If you go here,

you should be able to now select "Use secure cookies only"

Settings.png


loop Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.
Learn More

TNail
Member

@dennisedson setting "Use secure cookies only" fix "secure" attribute for JSESSIONID cookie. But it doesn't fix HTTPOnly attribute. Is there a plan to fix this as well?

 

0 Upvotes
kate4
Member

Hi @dennisedson !

Are there any updates?

0 Upvotes
Anonymous
Not applicable

@dennisedson 

Any developments on that front? We'd also need the cookies to be HttpOnly for security reasons.

0 Upvotes
dennisedson
Community Manager
Community Manager

@Anonymous , yep there has been development.  It is an alpha form and will be released as an in app feature.

I have a reminder set to check in on this later this month 😀 but please feel free to yell at me if I am not responsive.


loop Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.
Learn More

0 Upvotes
BGarcia09
Participant

@dennisedson Is there any update on this? It's 2026 now and my vulnerability scans still fail. I have enabled "Use secure cookies only" a long time ago. 

0 Upvotes
STierney
Community Manager
Community Manager

Hey @BGarcia09 - thanks for following up here!

Aside from re-tagging @dennisedson, I'd also like to tag in @RubenBurdin and @EValdes to see if either of them have any insight on there being any update regarding this.

Shane, Senior Community Moderator





loop


Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.

Learn More




0 Upvotes
CDavis45
Participant

@dennisedson, is there any update on this?  Maybe a work-around?  It's 2025 and my vulnerability scans are now failing do to the lack of HttpOnly.

KT17
Member

Any update on this? As this is needed for the same above reasons. 

 

Thanks

Anonymous
Not applicable

Awesome, thanks for the quick response. Looking forward to that 🙂

dennisedson
Community Manager
Community Manager

@joseph_costello 

Thank you so much for flagging!  I Will get this to the team to check it out


loop Loop Marketing is a new four-stage approach that combines AI efficiency and human authenticity to drive growth.
Learn More

0 Upvotes