10.13 Do not allow symbolic linking

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Symbolic links allow one application to include the libraries from another. This allows for re-use of code but also allows for potential security issues when applications include libraries from other applications they should not have access to.

Solution

In all context.xml, set the allowLinking attribute to false.

See Also

https://workbench.cisecurity.org/files/267

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Unix

Control ID: 5b6a16dc9414aac04e61d895a3778fa5f4e1f6623b3d523e3de76931ad8b2436