APIs & Integrations

joseph_costello
メンバー

PCI Compliance Failure

解決

Recently my website has started to fail PCI Compliance scans through Trustwave. Part of it is related to Hub Spot cookies.

 

DetectionDetails: Cookie Vulnerabilities Found __hssrc=1 Path = / Host = 0.0.0.0 Cookie does not have secure attribue in HTTPS Cookie does not have an HTTPOnly Attribute Cookie Change Observed on CLIENTside

 

 

We've migrated to the external merchant forms so we no longer need to worry about the PCI scan here, but I wanted to pass this along so Hubspot was aware. I'm not sure if the secure attribute can be set on the HS cookies, but might want to look into it. There were also other non-session cookies flagged in the scan to with other frameworks we used, so I don't know if its really a problem with them, or more of a problem with Trustwave's automated session cookie detection. 

1件の承認済みベストアンサー
dennisedson
解決策
HubSpot製品開発チーム
HubSpot製品開発チーム

PCI Compliance Failure

解決

@kate4 ,

Glad you asked 😜

If you go here,

you should be able to now select "Use secure cookies only"

Settings.png

元の投稿で解決策を見る

8件の返信
PPointPredict
メンバー

PCI Compliance Failure

解決

Hi all,

 

We found the following security issue from WANS scan report

Threat
The cookie does not contain the "HTTPOnly" attribute.
Impact
Cookies without the "HTTPOnly" attribute are permitted to be accessed via JavaScript. Cross-site scripting attacks can steal cookies which could lead to user
impersonation or compromise of the application account. 
Solution
If the associated risk of a compromised account is high, apply the "HTTPOnly" attribute to cookies.


Detection Information
Cookie Name(s)  messagesUtk, __hssc, __hssrc, __hstc, hubspotutk

0 いいね!
dennisedson
解決策
HubSpot製品開発チーム
HubSpot製品開発チーム

PCI Compliance Failure

解決

@kate4 ,

Glad you asked 😜

If you go here,

you should be able to now select "Use secure cookies only"

Settings.png

kate4
メンバー

PCI Compliance Failure

解決

Hi @dennisedson !

Are there any updates?

0 いいね!
Anonymous
適用対象外

PCI Compliance Failure

解決

@dennisedson 

Any developments on that front? We'd also need the cookies to be HttpOnly for security reasons.

0 いいね!
dennisedson
HubSpot製品開発チーム
HubSpot製品開発チーム

PCI Compliance Failure

解決

@Anonymous , yep there has been development.  It is an alpha form and will be released as an in app feature.

I have a reminder set to check in on this later this month 😀 but please feel free to yell at me if I am not responsive.

0 いいね!
KT17
メンバー

PCI Compliance Failure

解決

Any update on this? As this is needed for the same above reasons. 

 

Thanks

0 いいね!
Anonymous
適用対象外

PCI Compliance Failure

解決

Awesome, thanks for the quick response. Looking forward to that 🙂

dennisedson
HubSpot製品開発チーム
HubSpot製品開発チーム

PCI Compliance Failure

解決

@joseph_costello 

Thank you so much for flagging!  I Will get this to the team to check it out

0 いいね!