OpenStack Horizon - SESSION_COOKIE_HTTPONLY parameter set to True

Information

The 'HTTPONLY' cookie attribute instructs web browsers not to allow scripts (e.g. JavaScript or VBscript) an ability to access the cookies via the DOM document.cookie object. This session ID protection is mandatory to prevent session ID stealing through XSS attacks.

Solution

Set the value of parameter SESSION_COOKIE_HTTPONLY in /etc/openstack-dashboard/local_settings.py to True

See Also

http://docs.openstack.org/security-guide/dashboard/checklist.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23

Plugin: Unix

Control ID: de81276cce6d5db7e6e03a858859e8f553edbbf89b36bc35139e7b8d7845a370