Skip to content

Firefox must be configured to not automatically update installed add-ons and plugins.

An XCCDF Rule

Description

Firefox has a feature to permit installed add-ons and plugins to automatically update. The check may be disabled in an administrative policy by setting the ExtensionUpdate key under policies to false.

Rationale

Automatic updates from untrusted sites puts the entire enclave at risk and may override existing security settings.

ID
xccdf_org.ssgproject.content_rule_firefox_policy-extension_update
Severity
Medium
References
Updated



Remediation - Shell Script


firefox_cfg="policies.json"
# Default to /etc/firefox/policies to use for remediations.
firefox_dirs="/etc/firefox/policies"
permissions=644