SV-32766r2_rule
V-13738
WA000-WWA064
WA000-WWA064 A22
CAT II
10
Edit the httpd.conf file and ensure the LimitRequestFieldSize is explicitly configured and set to 8190 or other approved value.
To view the LimitRequestFieldSize value enter the following command:
grep "LimitRequestFieldSize" /usr/local/apache2/conf/httpd.conf.
If no LimitRequestFieldSize directives exist, this is a Finding. Although the default value is 8190, this directive must be explicitly set.
If the value of LimitRequestFieldSize is not set to 8190, this is a finding.
V-13738
False
WA000-WWA064 A22
To view the LimitRequestFieldSize value enter the following command:
grep "LimitRequestFieldSize" /usr/local/apache2/conf/httpd.conf.
If no LimitRequestFieldSize directives exist, this is a Finding. Although the default value is 8190, this directive must be explicitly set.
If the value of LimitRequestFieldSize is not set to 8190, this is a finding.
M
Web Administrator
158