1.4 Verify That the MYSQL_PWD Environment Variables Is Not In Use

Information

MySQL can read a default database password from an environment variable called MYSQL_PWD.

Solution

Check which users and/or scripts are setting MYSQL_PWD and change them to use a more secure method.

See Also

https://workbench.cisecurity.org/files/1623

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Unix

Control ID: a20f7d9998293aaaae02de3632ec142c0cf406ff8f2b47afc951a013ca78d0ad