Mozilla Firefox Security Technical Implementation Guide
Open a previous version of this SCAP benchmark.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-001274
- Version
- DTBF050
- Vuln IDs
- V-15768
- Rule IDs
- SV-16707r1_rule
Fix: F-15985r1_fix
Set the value of "security.default_personal_cert" to "Ask Every Time". Use the Mozilla.cfg file to lock the preference so users cannot change it.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF105
- Vuln IDs
- V-15771
- Rule IDs
- SV-16710r3_rule
Fix: F-15988r3_fix
Procedure: Set the value of "network.protocol-handler.external.shell" to "false" and lock using the Mozilla.cfg file.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTBF110
- Vuln IDs
- V-15772
- Rule IDs
- SV-16711r4_rule
Fix: F-15989r4_fix
Ensure the following extensions are not automatically opened by Firefox without user confirmation. Do not use plugins and add-ons to open these files. Use the "plugin.disable_full_page_plugin_for_types" preference to set and lock the following extensions so that an external application, rather than an add-on or plugin, will not be used: PDF, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, XLK, XLS, XLT, POT, PPS, PPT, DOS, DOT, WKS, BAT, PS, EPS, WCH, WCM, WB1, WB3, RTF, DOC, MDB, MDE, WBK, WB1, WCH, WCM, AD, ADP.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF140
- Vuln IDs
- V-15774
- Rule IDs
- SV-16713r2_rule
Fix: F-15991r2_fix
Ensure the preference “browser.formfill.enable" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF150
- Vuln IDs
- V-15775
- Rule IDs
- SV-16714r3_rule
Fix: F-15992r3_fix
Ensure the preference "signon.autofillForms" is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF160
- Vuln IDs
- V-15776
- Rule IDs
- SV-16715r2_rule
Fix: F-15993r2_fix
Ensure the preference “signon.rememberSignons“ is set and locked to the value of “false”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF180
- Vuln IDs
- V-15778
- Rule IDs
- SV-16717r1_rule
Fix: F-15995r1_fix
Ensure the preference "dom.disable_window_open_feature.status " is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF181
- Vuln IDs
- V-15779
- Rule IDs
- SV-16718r1_rule
Fix: F-15996r1_fix
Ensure the preference "dom.disable_window_move_resize" is set and locked to the value of “true”.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- DTBF030
- Vuln IDs
- V-15983
- Rule IDs
- SV-16925r8_rule
Fix: F-15984r8_fix
Configure the following parameters using the Mozilla.cfg file: LockPref "security.tls.version.min" is set to "2". LockPref "security.tls.version.max" is set to "4".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF182
- Vuln IDs
- V-15985
- Rule IDs
- SV-16927r1_rule
Fix: F-15997r1_fix
Ensure the preference "dom.disable_window_flip" is set and locked to the value of “true”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF183
- Vuln IDs
- V-15986
- Rule IDs
- SV-16928r2_rule
Fix: F-15998r4_fix
Ensure the preferences "dom.event.contextmenu.enabled" is set and locked to "false".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF090
- Vuln IDs
- V-19742
- Rule IDs
- SV-59603r1_rule
Fix: F-20415r2_fix
Set the preference “extensions.update.enabled” value to "false" and lock using the Mozilla.cfg file.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTBF070
- Vuln IDs
- V-19743
- Rule IDs
- SV-21889r9_rule
Fix: F-22495r7_fix
Ensure the required settings in "about:config" are locked using the "mozilla.cfg" file.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF085
- Vuln IDs
- V-19744
- Rule IDs
- SV-21890r1_rule
Fix: F-20416r2_fix
Ensure the preference "browser.search.update" is set and locked to the value of “False”.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF186
- Vuln IDs
- V-64891
- Rule IDs
- SV-79381r3_rule
Fix: F-70831r2_fix
Set the preference “xpinstall.enabled” to “false” and lock using the “mozilla.cfg” file. The “mozilla.cfg” file may need to be created if it does not already exist.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- DTBF190
- Vuln IDs
- V-79053
- Rule IDs
- SV-93759r3_rule
Fix: F-85803r3_fix
Ensure the preferences "datareporting.policy.dataSubmissionEnabled" is set and locked to "false".