UCF STIG Viewer Logo

Firefox automatically updates installed add-ons and plugins.


Overview

Finding ID Version Rule ID IA Controls Severity
V-19742 DTBF090 SV-59603r1_rule Medium
Description
Set this to false to disable checking for updated versions of the Extensions/Themes. Automatic updates from untrusted sites puts the enclave at risk of attack and may override security settings.
STIG Date
Mozilla FireFox Security Technical Implementation Guide 2020-06-19

Details

Check Text ( C-24188r1_chk )
Type "about:config" in the browser window. Verify the preference “extensions.update.enabled” is set to "false" and locked.

Criteria: If the parameter is set incorrectly, then this is a finding. If this setting is not locked, then this is a finding.
Fix Text (F-20415r2_fix)
Set the preference “extensions.update.enabled” value to "false" and lock using the Mozilla.cfg file.