1.8 MYSQL_PWD

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The use of the MYSQL_PWD environment variable implies the clear text storage of MySQL credentials. Avoiding this may increase assurance that the confidentiality of MySQL credentials is preserved.
NOTE : Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

MySQL can read the database password from an environmental variable called MYSQL_PWD. Verify MYSQL_PWD environmental variable not used

See Also

https://workbench.cisecurity.org/files/1613