Mozilla Firefox Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Firefox must be configured to not automatically update installed add-ons and plugins.
<VulnDiscussion>Set this to false to disable checking for updated versions of the Extensions/Themes. Automatic updates from untrusted sites p...Rule Medium Severity -
SRG-APP-000278
<GroupDescription></GroupDescription>Group -
Firefox must be configured to not automatically execute or download MIME types that are not authorized for auto-download.
<VulnDiscussion>Some files can be downloaded or execute without user interaction. This setting ensures these files are not downloaded and exe...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Firefox must be configured to disable form fill assistance.
<VulnDiscussion>To protect privacy and sensitive data, Firefox provides the ability to configure the program so that data entered into forms ...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Firefox must be configured to not automatically check for updated versions of installed search plugins.
<VulnDiscussion>Updates must be controlled and installed from authorized and trusted servers. This setting overrides a number of other settin...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
SRG-APP-000456
<GroupDescription></GroupDescription>Group -
The installed version of Firefox must be supported.
<VulnDiscussion>Using versions of an application that are not supported by the vendor is not permitted. Vendors respond to security flaws wit...Rule High Severity -
SRG-APP-000560
<GroupDescription></GroupDescription>Group -
Firefox must be configured to allow only TLS 1.2 or above.
<VulnDiscussion>Use of versions prior to TLS 1.2 are not permitted. SSL 2.0 and SSL 3.0 contain a number of security flaws. These versions mu...Rule High Severity -
SRG-APP-000177
<GroupDescription></GroupDescription>Group -
Firefox must be configured to ask which certificate to present to a website when a certificate is required.
<VulnDiscussion>When a website asks for a certificate for user authentication, Firefox must be configured to have the user choose which certi...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Firefox must be configured to not use a password store with or without a master password.
<VulnDiscussion>Firefox can be set to store passwords for sites visited by the user. These individual passwords are stored in a file and can ...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Firefox must be configured to block pop-up windows.
<VulnDiscussion>Pop-up windows may be used to launch an attack within a new browser window with altered settings. This setting blocks pop-up ...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
Firefox must be configured to prevent JavaScript from moving or resizing windows.
<VulnDiscussion>JavaScript can make changes to the browser's appearance. This activity can help disguise an attack taking place in a minimize...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.