[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-94547-7

Platform: cpe:/a:mozilla:firefox_rpmDate: (C)2021-06-15   (M)2023-07-04



A browser extension is a program that has been installed into the browser which adds functionality to it. Where a plug-in interacts only with a web page and usually a third party external application (Flash, Adobe Reader) an extension interacts with the browser program itself. Extensions are not embedded in web pages and must be downloaded and installed in order to work. Extensions allow browsers to avoid restrictions which apply to web pages. For example, an extension can be written to combine data from multiple domains and present it when a certain page is accessed which can be considered Cross Site Scripting. If a browser is configured to allow unrestricted use of extension then plug-ins can be loaded and installed from malicious sources and used on the browser.


Parameter:

[yes/no]


Technical Mechanism:

Set the preference xpinstall.enabled to false and lock using the mozilla.cfg file. The mozilla.cfg file may need to be created if it does not already exist.

CCSS Severity:CCSS Metrics:
CCSS Score : 6.6Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 4.7Privileges Required: NONE
Severity: MEDIUMUser Interaction: REQUIRED
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HScope: UNCHANGED
 Confidentiality: LOW
 Integrity: LOW
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:60318


OVAL    1
oval:org.secpod.oval:def:60318
XCCDF    1
xccdf_org.secpod_benchmark_stig_FIREFOX

© SecPod Technologies