Check: FFOX-00-000009
Mozilla Firefox STIG:
FFOX-00-000009
(in version v6 r1)
Title
Firefox must be configured to block pop-up windows. (Cat II impact)
Discussion
Pop-up windows may be used to launch an attack within a new browser window with altered settings. This setting blocks pop-up windows created while the page is loading.
Check Content
Type "about:policies" in the browser address bar. If "PopupBlocking" is not displayed under Policy Name or the Policy Value is not "Default" "true", this is a finding.
Fix Text
Windows group policy: 1. Open the group policy editor tool with "gpedit.msc". 2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Mozilla\Firefox\Popups Policy Name: Block pop-ups from websites Policy State: Enabled macOS "plist" file: Add the following: <key>PopupBlocking</key> <true/> Linux "policies.json" file: Add the following in the policies section: "PopupBlocking": true
Additional Identifiers
Rule ID: SV-251553r807131_rule
Vulnerability ID: V-251553
Group Title: SRG-APP-000141
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
The organization configures the information system to provide only essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |