UCF STIG Viewer Logo

HAProxy must have the latest approved security-relevant software updates installed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-89215 VRAU-HA-000480 SV-99865r1_rule Medium
Description
All vRA components, to include Lighttpd, are under VMware configuration management control. The CM process ensures that all patches, functions, and modules have been thoroughly tested before being introduced into the production version. By using the most current version of Lighttpd, the Lighttpd server will always be using the most stable and known baseline.
STIG Date
VMW vRealize Automation 7.x HA Proxy Security Technical Implementation Guide 2018-10-12

Details

Check Text ( C-88907r1_chk )
Interview the ISSO.

Determine whether HAProxy has the latest approved security-relevant software updates and updates are installed within the identified time period.

If the latest approved security-relevant software updates are not installed or installed within the identified time period, this is a finding.
Fix Text (F-95957r2_fix)
Ensure HAProxy has the latest approved security-relevant software updates and the updates are installed within the identified time period.