SameSite None Without Secure
ID |
csharp.samesite_none_without_secure |
Severity |
low |
Remediation Complexity |
low |
Remediation Risk |
low |
Remediation Effort |
low |
Resource |
Misconfiguration |
Language |
CSharp |
Tags |
ASVS50:v3.4.3, CWE:1275, NIST.SP.800-53, OWASP:2025:A05, PCI-DSS:6.5.10 |
Description
An ASP.NET Core cookie is configured with SameSite = SameSiteMode.None but is not marked Secure. The CookieOptions (or CookieBuilder) sets the cross-site policy to None without enabling Secure = true (or SecurePolicy = CookieSecurePolicy.Always).
Rationale
SameSite=None tells the browser to send the cookie on cross-site requests, re-enabling the exact behaviour that the SameSite mechanism exists to restrain. Modern browsers therefore only accept a SameSite=None cookie when it is also marked Secure; a cookie that is None without Secure is either rejected outright or, on older clients, transmitted over plain HTTP.
Omitting Secure on a cross-site cookie exposes it to interception over insecure transport and re-opens the CSRF surface that SameSite was meant to close. Session and authentication cookies configured this way can be leaked or replayed.
// VULNERABLE: cross-site cookie is not marked Secure
var options = new CookieOptions
{
SameSite = SameSiteMode.None
};
Response.Cookies.Append("session", value, options);
Remediation
When a cookie must be sent cross-site (SameSite=None), always mark it Secure so it is only transmitted over HTTPS. For CookieOptions set Secure = true; for a CookieBuilder set SecurePolicy = CookieSecurePolicy.Always. If the cookie does not need to be sent cross-site, prefer SameSiteMode.Lax or SameSiteMode.Strict.
var options = new CookieOptions
{
SameSite = SameSiteMode.None,
Secure = true // FIXED
};