Mozilla Firefox Security Technical Implementation Guide
Open a previous version of this SCAP benchmark.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001274
- Version
- DTBF050
- Vuln IDs
- V-15768
- Rule IDs
- SV-16707r1_rule
Fix: F-15985r1_fix
Set the value of "security.default_personal_cert" to "Ask Every Time". Use the Mozilla.cfg file to lock the preference so users cannot change it.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF105
- Vuln IDs
- V-15771
- Rule IDs
- SV-16710r3_rule
Fix: F-15988r3_fix
Procedure: Set the value of "network.protocol-handler.external.shell" to "false" and lock using the Mozilla.cfg file.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTBF110
- Vuln IDs
- V-15772
- Rule IDs
- SV-16711r4_rule
Fix: F-15989r4_fix
Ensure the following extensions are not automatically opened by Firefox without user confirmation. Do not use plugins and add-ons to open these files. Use the "plugin.disable_full_page_plugin_for_types" preference to set and lock the following extensions so that an external application, rather than an add-on or plugin, will not be used: PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT, PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF140
- Vuln IDs
- V-15774
- Rule IDs
- SV-16713r2_rule
Fix: F-15991r2_fix
Ensure the preference “browser.formfill.enable" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF150
- Vuln IDs
- V-15775
- Rule IDs
- SV-16714r3_rule
Fix: F-15992r3_fix
Ensure the preference "signon.autofillForms" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF160
- Vuln IDs
- V-15776
- Rule IDs
- SV-16715r2_rule
Fix: F-15993r2_fix
Ensure the preference “signon.rememberSignons“ is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF180
- Vuln IDs
- V-15778
- Rule IDs
- SV-16717r1_rule
Fix: F-15995r1_fix
Ensure the preference "dom.disable_window_open_feature.status " is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF181
- Vuln IDs
- V-15779
- Rule IDs
- SV-16718r1_rule
Fix: F-15996r1_fix
Ensure the preference "dom.disable_window_move_resize" is set and locked to the value of “true”.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- DTBF030
- Vuln IDs
- V-15983
- Rule IDs
- SV-16925r7_rule
Fix: F-15984r7_fix
Configure the following parameters using the Mozilla.cfg file: LockPref "security.tls.version.min" is set to "2". LockPref "security.tls.version.max" is set to "3".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF182
- Vuln IDs
- V-15985
- Rule IDs
- SV-16927r1_rule
Fix: F-15997r1_fix
Ensure the preference "dom.disable_window_flip" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF183
- Vuln IDs
- V-15986
- Rule IDs
- SV-16928r2_rule
Fix: F-15998r4_fix
Ensure the preferences "dom.event.contextmenu.enabled" is set and locked to "false".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF090
- Vuln IDs
- V-19742
- Rule IDs
- SV-59603r1_rule
Fix: F-20415r2_fix
Set the preference “extensions.update.enabled” value to "false" and lock using the Mozilla.cfg file.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTBF070
- Vuln IDs
- V-19743
- Rule IDs
- SV-21889r9_rule
Fix: F-22495r7_fix
Ensure the required settings in "about:config" are locked using the "mozilla.cfg" file.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF085
- Vuln IDs
- V-19744
- Rule IDs
- SV-21890r1_rule
Fix: F-20416r2_fix
Ensure the preference "browser.search.update" is set and locked to the value of “False”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF186
- Vuln IDs
- V-64891
- Rule IDs
- SV-79381r3_rule
Fix: F-70831r2_fix
Set the preference “xpinstall.enabled” to “false” and lock using the “mozilla.cfg” file. The “mozilla.cfg” file may need to be created if it does not already exist.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF190
- Vuln IDs
- V-79053
- Rule IDs
- SV-93759r2_rule
Fix: F-85803r2_fix
Ensure the preferences "datareporting.policy.dataSubmissionEnabled" is set and locked to "false". Ensure the preferences "datareporting.healthreport.service.enabled" is set and locked to "false". Ensure the preferences "datareporting.healthreport.uploadEnabled" is set and locked to "false".