← 문제 라이브러리
Security Intermediate SECURITY-017 · 20 min

Session cookie becomes insecure after CDN to origin scheme mismatch

Users arrive over HTTPS, but origin headers make the app think the request is plain HTTP and weaken the session cookie flags.

WAF / AppSecPro
시나리오

Users arrive over HTTPS, but origin headers make the app …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기