Disable Automatic Search And Installation of Plugins
An XCCDF Rule
Description
Chromium will automatically detect, search, and install plugins as required. This should be disabled by settingDisablePluginFinder
to true
in the
Chromium policy file.
Rationale
The automatic search and installation of missing or not installed plugins should be disabled as this can cause significant risk if a unapproved or vulnerable plugin were to be installed without proper permissions or authorization.
- ID
- xccdf_org.ssgproject.content_rule_chromium_disable_automatic_installation
- Severity
- Unknown
- References
- Updated
Remediation Templates
A Shell Script
if ! grep -q DisablePluginFinder /etc/chromium/policies/managed/chrome_stig_policy.json; then
sed -i -e '/{/a \ "'DisablePluginFinder'": 'true',' /etc/chromium/policies/managed/chrome_stig_policy.json
else
sed -i -e 's/\"'DisablePluginFinder'.*/\"'DisablePluginFinder'\": 'true',/g' /etc/chromium/policies/managed/chrome_stig_policy.json
fi