1.4 Verify that 'MYSQL_PWD' Is Not Set

Information

The use of the MYSQL_PWD environment variable implies the clear text storage of MySQL credentials.

Solution

Check which users and/or scripts are setting MYSQL_PWD and change them to use a more secure method.

See Also

https://workbench.cisecurity.org/files/1619

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c)

Plugin: Unix

Control ID: d6f10ca59489230957f0e7d01763fcb3310228ec79243581814bd070e4b4c527