10.3 Enusre the Maximum Request Header Field Size Is Set Properly

Information

The 'LimitRequestFieldSize' directive sets the maximum size of an HTTP request header field. It is recommended that the 'LimitRequestFieldSize' directive be set to '1024' or less.

Rationale:

Limiting header field size may reduce the exposure of a buffer-related vulnerability potentially present in a code base hosted by Apache HTTP server.

Solution

Perform the following to implement the recommended state:

Add or modify the 'LimitRequestFieldSize' directive in the Apache configuration to have a value of '1024' or less.

See Also

https://workbench.cisecurity.org/files/2020

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|9

Plugin: Unix

Control ID: 216bb3196cd7efbc6f7e6091370b0446d605641d38c59d9c4fa35bd6cd75d113