1.1.18.10 (L1) Ensure 'security.mixed_content.block_active_content' is set to 'Enabled'

Information

This policy setting configures the ability to view HTTP content such as JavaScript, CSS, objects, and xhr requests.

The recommended state for this setting is: Enabled

Blocking active mixed content minimizes the risk of man-in-the-middle attacks.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\security.mixed_content.block_active_content

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-8, CSCv7|7.9

Plugin: Windows

Control ID: b9049b4a98200da4e71ed2dda51aa47edabb47b618c89ba2e824c250fca2ad59