5.2.6 Ensure the sudoers file restricts sudo access to authorized personnel - sudoers.d

Information

The Linux operating system must restrict privilege elevation to authorized personnel.

Rationale:

The sudo command allows a user to execute programs with elevated (administrator) privileges. It prompts the user for their password and confirms your request to execute a command by checking a file, called sudoers. If the 'sudoers' file is not configured correctly, any user defined on the system can initiate privileged actions on the target system.

Solution

Remove the following entries from the sudoers file:

ALL ALL=(ALL) ALL
ALL ALL=(ALL:ALL) ALL

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CCI|CCI-000366, CSCv7|4.3, Rule-ID|SV-237633r646850_rule, STIG-ID|RHEL-07-010341

Plugin: Unix

Control ID: 32f1ca9be54d8f6bcf94a564e76b2d925dc83bbdcb4955f25aba3b589f8dd933