STIGUI
V-26327CAT II — Medium severitySV-33229r1_rule

The URL-path name must be set to the file path name or the directory path name.

Rule version WA00560 A22 · STIG v1 · 2019-01-07

Discussion

The ScriptAlias directive controls which directories the Apache server "sees" as containing scripts. If the directive uses a URL-path name that is different than the actual file system path, the potential exists to expose the script source code.

Check

Enter the following command:

grep "ScriptAlias" /usr/local/apache2/conf/httpd.conf.

If any enabled ScriptAlias directive do not have matching URL-path and file-path or directory-path entries, this is a finding.

Fix

Edit the httpd.conf file and set the ScriptAlias URL-path and file-path or directory-path entries.

Identifiers

Group ID
V-26327
Group title
WA00560
Rule ID
SV-33229r1_rule
Check ID
C-33784r1_chk
Fix ID
F-29427r1_fix