5.2 Disable Scripting of Plugins by JavaScript

Information

Javascript can initiate and interact with the Plug-ins installed in Firefox.
This may reduce a malicious script's ability to exploit vulnerabilities in plug-ins or abuse plug-in features.

Solution

Perform the following procedure:

* Open the mozilla.cfg file in the installation directory with a text editor

* Add the following lines to mozilla.cfg:

lockPref("security.xpconnect.plugin.unrestricted", false);

See Also

https://workbench.cisecurity.org/files/1158

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 6a0cc84c3c2d34bda9009694bf70d7b41a6cf024be3e14969b9cc03bcea27eeb