The TRACE method must be disabled.
An XCCDF Rule
Description
Use the Apache TraceEnable directive to disable the HTTP TRACE request method. Refer to the Apache documentation for more details http://httpd.apache.org/docs/2.2/mod/core.html#traceenable. The HTTP 1.1 protocol requires support for the TRACE request method which reflects the request back as a response and was intended for diagnostics purposes. The TRACE method is not needed and is easily subject to abuse and should be disabled.
Property | Value |
---|---|
Responsibility | Web Administrator |
- ID
- SV-33183r1_rule
- Version
- WA00550 W22
- Severity
- Medium
- Updated
Remediation Templates
A Manual Procedure
Disable the TraceEnable directive by setting it to "off".