Information
Amazon Linux 2023 must insure all interactive users have a primary group that exists.
GROUP ID: V-274159RULE ID: SV-274159r1120465
If a user is assigned the group identifier (GID) of a group that does not exist on the system, and a group with the GID is subsequently created, the user may have unintended rights to any files associated with the group.
Satisfies: SRG-OS-000104-GPOS-00051, SRG-OS-000121-GPOS-00062, SRG-OS-000042-GPOS-00020
Solution
Configure Amazon Linux 2023 so that all GIDs are referenced in "/etc/passwd" are defined in "/etc/group".
Edit the file "/etc/passwd" and ensure that every user's GID is a valid GID.
Item Details
Category: AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION
References: 800-53|AU-3(1), 800-53|IA-2, 800-53|IA-8, CAT|II, CCI|CCI-000135, CCI|CCI-000764, CCI|CCI-000804, Rule-ID|SV-274159r1120465_rule, STIG-ID|AZLX-23-002480, Vuln-ID|V-274159
Control ID: 4fdba19ddc9fa4759494752bf46fcfaa98a15bc45d443734023fe5bd837365c4