10.14 Do not allow symbolic linking

Information

Symbolic links allow one application to include the libraries from another. This allows for re-use of code but also allows for potential security issues when applications include libraries from other applications they should not have access to.

Solution

In all context.xml, set the allowLinking attribute to false.

See Also

https://workbench.cisecurity.org/files/266

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 5233d2943903175be0041f00e9892d19bc3f8f7eba55f5e5837fc630d345538c