| name | cis-apache24-5.7 |
| description | Ensure HTTP Request Methods Are Restricted |
| category | cis-apache |
| version | 2.3.0 |
| author | cyberstrike-official |
| tags | ["cis","apache","linux","features","content","options"] |
| cis_id | 5.7 |
| cis_benchmark | CIS Apache HTTP Server 2.4 Benchmark v2.3.0 |
| tech_stack | ["linux","apache"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
5.7 Ensure HTTP Request Methods Are Restricted
Profile Applicability
Description
Use the Apache <LimitExcept> directive to restrict unnecessary HTTP request methods of the web server to only accept and process the GET, HEAD, POST and OPTIONS HTTP request methods.
Rationale
The HTTP 1.1 protocol supports several request methods which are rarely used and potentially high risk. For example, methods such as PUT and DELETE are rarely used and should be disabled in keeping with the primary security principal of minimize features and options. Also since the usage of these methods is typically to modify resources on the web server, they should be explicitly disallowed. For normal web server operation, you will typically need to allow only the GET, HEAD and POST request methods. This will allow for downloading of web pages and submitting information to web forms. The OPTIONS request method will also be allowed as it used to request which HTTP request methods are allowed. Unfortunately, the Apache <LimitExcept> directive does not deny the TRACE request method. The TRACE request method will be disallowed in another benchmark recommendation with the TraceEnable directive.
Audit
Perform the following to determine if the recommended state is implemented:
Locate the Apache configuration files and included configuration files.
Search for all directives other than the OS root directory.
Ensure that either one of the following three methods are configured:
Using the deprecated Order/Deny/Allow method:
- Within each section, ensure that there is a single directive containing a value of
Order deny, allow.
- Verify the directive does not include any HTTP methods other than GET, POST, and OPTIONS. (It may contain fewer methods.)
The section should resemble this example:
<Directory /var/www/html>
# other directives
<LimitExcept GET POST OPTIONS>
Order deny, allow
</LimitExcept>
</Directory>
Using the Require method:
- Within each section, ensure that there is a single directive containing a single instance of
Require all denied.
- Ensure there are no Allow or Deny directives in the root element.