UCF STIG Viewer Logo

The Horizon Connection Server must have X-Frame-Options enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-246907 HRZV-7X-000026 SV-246907r768681_rule Medium
Description
RFC 7034 HTTP Header Field X-Frame-Options, also known as counter clickjacking, is enabled by default on the Horizon Connection Server. It can be disabled by adding the entry "x-frame-options=OFF" to the locked.properties file, usually for troubleshooting purposes. The default configuration must be verified and maintained.
STIG Date
VMware Horizon 7.13 Connection Server Security Technical Implementation Guide 2021-07-30

Details

Check Text ( C-50339r768679_chk )
On the Horizon Connection Server, navigate to "\VMware\VMware View\Server\sslgateway\conf".

If a file named "locked.properties" does not exist in this path, this is NOT a finding.

Open "locked.properties" in a text editor. Find the "X-Frame-Options" setting.

If there is no "X-Frame-Options" setting, this is NOT a finding.

If "X-Frame-Options" is set to "OFF", this is a finding.
Fix Text (F-50293r768680_fix)
On the Horizon Connection Server, navigate to "\VMware\VMware View\Server\sslgateway\conf".

Open "locked.properties" in a text editor. Remove the following line:

X-Frame-Options=OFF

Save and close the file. Restart the "VMware Horizon View Connection Server" service for changes to take effect.