10.10 Configure maxHttpHeaderSize

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The maxHttpHeaderSize limits the size of the request and response headers defined in bytes.

Limiting the size of the header request can help protect against Denial of Service (DoS) requests.

Solution

Set maxHttpHeaderSize for each connector in $CATALINA_HOME/conf/server.xml to the appropriate setting.

maxHttpHeaderSize="8192"

See Also

https://workbench.cisecurity.org/benchmarks/15137