DTBF183 - Firefox is configured to allow JavaScript to disable or replace context menus - dom.event.contextmenu.enabled

Information

A context menu (also known as a pop-up menu) is often used in a graphical user interface (GUI) and appears upon user interaction (e.g., a right mouse click). A context menu offers a limited set of choices that are available in the current state, or context, of the operating system or application. A website may execute JavaScript that can make changes to these context menus. This can help disguise an attack. Set this preference to 'false' so that webpages will not be able to affect the context menu event.

Solution

Ensure the preferences 'dom.event.contextmenu.enabled' is set and locked to 'false'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MOZ_Firefox_V5R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-223166r612236_rule, STIG-ID|DTBF183, STIG-Legacy|SV-16928, STIG-Legacy|V-15986, Vuln-ID|V-223166

Plugin: Windows

Control ID: c374f35edf911396c0e5df4fddd6c0db9ee3f0abad90e44e59227404040f27e9