37 - Configure maxHttpHeaderSize

Information

The maxHttpHeaderSize limits the size of the request and response headers and is defined in bytes. If not specified, the default is 8192 bytes.

Limiting the size of the header request can help protect against Denial of Service requests.

Solution

Within $JETTY_HOME/etc/server.xml ensure each connector is configured to the appropriate maxHttpHeaderSize setting.
maxHttpHeaderSize="8192"

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Unix

Control ID: c76df9f3e5fe9399374307a93a9f3c398dad6c133ab022cfe42bc289b38acff6