DTBF182 - Firefox is configured to allow JavaScript to raise or lower windows.

Information

JavaScript can make changes to the browser's appearance. Allowing a website to use JavaScript to raise and lower browser windows may disguise an attack. Browser windows may not be set as active via JavaScript.

Solution

Ensure the preference 'dom.disable_window_flip' is set and locked to the value of 'true'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V5R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-223165r612236_rule, STIG-ID|DTBF182, STIG-Legacy|SV-16927, STIG-Legacy|V-15985, Vuln-ID|V-223165

Plugin: Windows

Control ID: 251fce93ac2ffbe6db7959b17481e122c30a9fbfd181fb5b49ed8779c6f5e31d