5.10 Securely Define Stored Procedures and Functions DEFINER and INVOKER

Information

Stored procedure and stored function declarations include a definition of permissions which can be used to escalate permissions. It's important to inspect these settings to ensure they do not unnecessarily escalate privileges.

Rationale:

A stored procedure or function that improperly escalates privileges may provide unintended access rights which can be improperly used.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Drop and recreate stored procedures and functions using proper DEFINER and INVOKER settings, or other code changes.

See Also

https://workbench.cisecurity.org/files/3848

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8, CSCv7|14.6

Plugin: MySQLDB

Control ID: 69ae210cc6d8d5795951d40432518c74807959e7c1d67fed9475f226fb4a5a95