Skip to content

Basic authentication for RSS feeds over HTTP must not be used.

An XCCDF Rule

Description

Basic authentication uses plain text passwords that could be used to compromise a system.

ID
SV-253408r958478_rule
Version
WN11-CC-000300
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

The default behavior is for the Windows RSS platform to not use Basic authentication over HTTP connections.

To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> RSS Feeds >> "Turn on Basic feed authentication over HTTP" to "Not Configured" or "Disabled".