42 - Do not allow cross context requests

Information

Setting crossContext to true allows for an application to call ServletConext.getContext to return a dispatcher for another application.

Allowing crossContext creates the possibility for a malicious application to make requests to a restricted application.

Solution

In all context.xml, set the crossContext attribute to false.
By default crossContext has a value of false.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: c6bf5ef2b0864daf05d7cc0f16295ea3e0c75565f75b5e632664337c1be5726a