10.1 Ensure the Maximum Request Line Length Is Set Properly

Information

The 'LimitRequestLine' directive sets the maximum number of bytes that Apache will read for each line of an HTTP request. It is recommended that the 'LimitRequestLine' be set to '512' or less.

Rationale:

Limiting request line size may reduce the exposure of a buffer-related vulnerability potentially present in a code base hosted by Apache HTTP server.

Solution

Perform the following to implement the recommended state:

Add or modify the 'LimitRequestLine' directive in the Apache configuration to have a value of '512' or less.

LimitRequestLine 512

See Also

https://workbench.cisecurity.org/files/2020

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|9

Plugin: Unix

Control ID: f0b07768384442400870ef71d1eb328e32c5ec27b405b3bb3aa54bb45e8b6575