Skip to content

Firefox must be configured to not automatically update installed add-ons and plugins.

An XCCDF Rule

Description

Set this to false to disable checking for updated versions of the Extensions/Themes. Automatic updates from untrusted sites puts the enclave at risk of attack and may override security settings.

ID
SV-251549r879587_rule
Version
FFOX-00-000005
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Windows group policy:
1. Open the group policy editor tool with "gpedit.msc".
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Mozilla\Firefox\Extensions
Policy Name: Extension Update
Policy State: Disabled