OSSN-0037: Configure Horizon to mitigate BREACH/CRIME attacks

Summary

Horizon is vulnerable to BREACH/CRIME style chosen plaintext attacks in it’s default configuration.

Affected Services / Software

Horizon, Django, Apache, Nginx, SSL, TLS

Discussion

The BREACH attack may be used to compromise Django’s cross-site request forgery (CSRF) protection. OpenStack’s Horizon web dashboard is built on the Django framework, and is consequently affected. There is no fix available in Horizon itself, but there are protection options.

BREACH takes advantage of vulnerabilities when serving compressed data over SSL/TLS.

Contacts / References

Author: Robert Clark, HP