Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-246907 | HRZV-7X-000026 | SV-246907r768681_rule | Medium |
Description |
---|
RFC 7034 HTTP Header Field X-Frame-Options, also known as counter clickjacking, is enabled by default on the Horizon Connection Server. It can be disabled by adding the entry "x-frame-options=OFF" to the locked.properties file, usually for troubleshooting purposes. The default configuration must be verified and maintained. |
STIG | Date |
---|---|
VMware Horizon 7.13 Connection Server Security Technical Implementation Guide | 2021-07-30 |
Check Text ( C-50339r768679_chk ) |
---|
On the Horizon Connection Server, navigate to " If a file named "locked.properties" does not exist in this path, this is NOT a finding. Open "locked.properties" in a text editor. Find the "X-Frame-Options" setting. If there is no "X-Frame-Options" setting, this is NOT a finding. If "X-Frame-Options" is set to "OFF", this is a finding. |
Fix Text (F-50293r768680_fix) |
---|
On the Horizon Connection Server, navigate to " Open "locked.properties" in a text editor. Remove the following line: X-Frame-Options=OFF Save and close the file. Restart the "VMware Horizon View Connection Server" service for changes to take effect. |