From abd77c341cff7698e72880a3d028e2bd74ce0e47 Mon Sep 17 00:00:00 2001 From: Eric Jenkins Date: Fri, 15 Sep 2023 11:45:02 -0400 Subject: [PATCH 1/4] update V-221596 --- .../Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log index 38ff6f0f7..2bf49df00 100644 --- a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log +++ b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log @@ -7,7 +7,7 @@ V-221563::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Ke V-221564::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DefaultSearchProviderName'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'an organization approved encrypted search provider'"} V-221565::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DefaultSearchProviderSearchURL'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'an organization-approved encrypted search string'"} V-221588::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DownloadRestrictions'; ValueType = 'Dword'; ValueData = $null; OrganizationValueTestString = "{0} -eq '1|2'"} -V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'AutoplayAllowlist'; ValueType = 'MultiString'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} +V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist'; ValueName = '1'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} V-234701::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'SSLVersionMin'; ValueType = 'String'; ValueData = 'tls1.2'} V-245539::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Absent'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'CookiesSessionOnlyForUrls'} V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = 'CookiesSessionOnlyForUrls'; ValueType = 'String'; ValueData = 'javascript://*'} From ad8238ff6960d7a6d8b891d522f10be4ccd55568 Mon Sep 17 00:00:00 2001 From: Eric Jenkins Date: Fri, 15 Sep 2023 12:01:20 -0400 Subject: [PATCH 2/4] add update for V-221596 --- .../Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log | 2 +- .../StigData/Processed/Google-Chrome-2.7.org.default.xml | 2 +- source/StigData/Processed/Google-Chrome-2.7.xml | 8 ++++---- .../StigData/Processed/Google-Chrome-2.8.org.default.xml | 2 +- source/StigData/Processed/Google-Chrome-2.8.xml | 8 ++++---- 5 files changed, 11 insertions(+), 11 deletions(-) diff --git a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log index 38ff6f0f7..2bf49df00 100644 --- a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log +++ b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log @@ -7,7 +7,7 @@ V-221563::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Ke V-221564::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DefaultSearchProviderName'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'an organization approved encrypted search provider'"} V-221565::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DefaultSearchProviderSearchURL'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'an organization-approved encrypted search string'"} V-221588::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'DownloadRestrictions'; ValueType = 'Dword'; ValueData = $null; OrganizationValueTestString = "{0} -eq '1|2'"} -V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'AutoplayAllowlist'; ValueType = 'MultiString'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} +V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist'; ValueName = '1'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} V-234701::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'SSLVersionMin'; ValueType = 'String'; ValueData = 'tls1.2'} V-245539::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Absent'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'CookiesSessionOnlyForUrls'} V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = 'CookiesSessionOnlyForUrls'; ValueType = 'String'; ValueData = 'javascript://*'} diff --git a/source/StigData/Processed/Google-Chrome-2.7.org.default.xml b/source/StigData/Processed/Google-Chrome-2.7.org.default.xml index 7d592f5fe..0476e0f20 100644 --- a/source/StigData/Processed/Google-Chrome-2.7.org.default.xml +++ b/source/StigData/Processed/Google-Chrome-2.7.org.default.xml @@ -13,7 +13,7 @@ - + diff --git a/source/StigData/Processed/Google-Chrome-2.7.xml b/source/StigData/Processed/Google-Chrome-2.7.xml index 047408bca..75e9ad827 100644 --- a/source/StigData/Processed/Google-Chrome-2.7.xml +++ b/source/StigData/Processed/Google-Chrome-2.7.xml @@ -1,4 +1,4 @@ - + <VulnDiscussion>Google Chrome is being continually updated by the vendor in order to address identified security vulnerabilities. Running an older version of the browser can introduce security vulnerabilities to the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> @@ -698,7 +698,7 @@ Windows method: Present False - HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome + HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist V-81589 True {0} -eq 'a list of administrator-approved URLs @@ -711,8 +711,8 @@ Windows method: 2. Navigate to HKLM\Software\Policies\Google\Chrome\ 3. If the “AutoplayAllowlist” key may contain a list of administrator-approved URLs. This requirement is optional. - AutoplayAllowlist - MultiString + 1 + String <VulnDiscussion>Enable URL-keyed anonymized data collection in Google Chrome and prevent users from changing this setting. diff --git a/source/StigData/Processed/Google-Chrome-2.8.org.default.xml b/source/StigData/Processed/Google-Chrome-2.8.org.default.xml index 0784de38a..b20873e5d 100644 --- a/source/StigData/Processed/Google-Chrome-2.8.org.default.xml +++ b/source/StigData/Processed/Google-Chrome-2.8.org.default.xml @@ -13,7 +13,7 @@ - + diff --git a/source/StigData/Processed/Google-Chrome-2.8.xml b/source/StigData/Processed/Google-Chrome-2.8.xml index 245f381d5..5e050cf93 100644 --- a/source/StigData/Processed/Google-Chrome-2.8.xml +++ b/source/StigData/Processed/Google-Chrome-2.8.xml @@ -1,4 +1,4 @@ - + <VulnDiscussion>Google Chrome is being continually updated by the vendor in order to address identified security vulnerabilities. Running an older version of the browser can introduce security vulnerabilities to the system.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls> @@ -698,7 +698,7 @@ Windows method: Present False - HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome + HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist V-81589 True {0} -eq 'a list of administrator-approved URLs @@ -711,8 +711,8 @@ Windows method: 2. Navigate to HKLM\Software\Policies\Google\Chrome\ 3. If the “AutoplayAllowlist” key may contain a list of administrator-approved URLs. This requirement is optional. - AutoplayAllowlist - MultiString + 1 + String <VulnDiscussion>Enable URL-keyed anonymized data collection in Google Chrome and prevent users from changing this setting. From effdf45884691614548acec2f9789c5c99268fbe Mon Sep 17 00:00:00 2001 From: Eric Jenkins Date: Fri, 15 Sep 2023 12:04:40 -0400 Subject: [PATCH 3/4] update changelog --- CHANGELOG.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index ab2b8893c..e616ccfcd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## [Unreleased] +* Fix for Chrome issue Registry Path is incorrect [#1215](https://github.com/microsoft/PowerStig/issues/1215) + ## [4.18.0] - 2023-09-05 * Update PowerSTIG to Parse/Apply Red Hat Enterprise Linux 7 STIG V3R12: [#1254](https://github.com/microsoft/PowerStig/issues/1254) From ba0cb06942544a7fd005586dda4e85abc2e2be77 Mon Sep 17 00:00:00 2001 From: Eric Jenkins Date: Fri, 15 Sep 2023 12:13:41 -0400 Subject: [PATCH 4/4] add update for V-221572 --- .../Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log | 2 +- .../Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log | 2 +- source/StigData/Processed/Google-Chrome-2.7.xml | 2 +- source/StigData/Processed/Google-Chrome-2.8.xml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log index 2bf49df00..53118185b 100644 --- a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log +++ b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R7_Manual-xccdf.log @@ -10,4 +10,4 @@ V-221588::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Ke V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist'; ValueName = '1'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} V-234701::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'SSLVersionMin'; ValueType = 'String'; ValueData = 'tls1.2'} V-245539::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Absent'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'CookiesSessionOnlyForUrls'} -V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = 'CookiesSessionOnlyForUrls'; ValueType = 'String'; ValueData = 'javascript://*'} +V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = '1'; ValueType = 'String'; ValueData = 'javascript://*'} diff --git a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log index 2bf49df00..53118185b 100644 --- a/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log +++ b/source/StigData/Archive/Chrome/U_Google_Chrome_STIG_V2R8_Manual-xccdf.log @@ -10,4 +10,4 @@ V-221588::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Ke V-221596::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\AutoplayAllowlist'; ValueName = '1'; ValueType = 'String'; ValueData = $null; OrganizationValueTestString = "{0} -eq 'a list of administrator-approved URLs"} V-234701::*::HardCodedRule(RegistryRule)@{DscResource = 'RegistryPolicyFile'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'SSLVersionMin'; ValueType = 'String'; ValueData = 'tls1.2'} V-245539::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Absent'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome'; ValueName = 'CookiesSessionOnlyForUrls'} -V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = 'CookiesSessionOnlyForUrls'; ValueType = 'String'; ValueData = 'javascript://*'} +V-221572::*::HardCodedRule(RegistryRule)@{DscResource = 'Registry'; Ensure = 'Present'; Key = 'HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\URLBlocklist'; ValueName = '1'; ValueType = 'String'; ValueData = 'javascript://*'} diff --git a/source/StigData/Processed/Google-Chrome-2.7.xml b/source/StigData/Processed/Google-Chrome-2.7.xml index 75e9ad827..30dc82a88 100644 --- a/source/StigData/Processed/Google-Chrome-2.7.xml +++ b/source/StigData/Processed/Google-Chrome-2.7.xml @@ -283,7 +283,7 @@ Windows method: javascript://* - CookiesSessionOnlyForUrls + 1 String diff --git a/source/StigData/Processed/Google-Chrome-2.8.xml b/source/StigData/Processed/Google-Chrome-2.8.xml index 5e050cf93..891a4fc57 100644 --- a/source/StigData/Processed/Google-Chrome-2.8.xml +++ b/source/StigData/Processed/Google-Chrome-2.8.xml @@ -283,7 +283,7 @@ Windows method: javascript://* - CookiesSessionOnlyForUrls + 1 String