1.6 Verify That 'MYSQL_PWD' Is Not Set In Users' Profiles

Information

MySQL can read a default database password from an environment variable called MYSQL_PWD.

Solution

Check which users and/or scripts are setting MYSQL_PWD and change them to use a more secure method.

See Also

https://workbench.cisecurity.org/files/1617

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CSCv6|16.13, CSCv6|16.14

Plugin: Windows

Control ID: d7284b998fc2f53eeaf26bafad8f10b26e85efddb2186af4b7f5033c3fe2d9d9