OpenStack Horizon - CSRF_COOKIE_SECURE parameter set to True

Information

CSRF (Cross-site request forgery) is an attack which forces an end user to execute unauthorized commands on a web application in which he/she is currently authenticated. A successful CSRF exploit can compromise end user data and operations in case of normal user. If the targeted end user has admin privileges, this can compromise the entire web application.

Solution

Set the value of parameter CSRF_COOKIE_SECURE in /etc/openstack-dashboard/local_settings.py to True

See Also

http://docs.openstack.org/security-guide/dashboard/checklist.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23

Plugin: Unix

Control ID: 4b91825e883a770860ce9108a9351666acc05bbbe46d4842b3fc77327fc4724a