Information
sudo timestamp_timeout controls how long a user's sudo privileges remain active after the initial password entry.
A timeout value reduces the window of opportunity for unauthorized privileged sudo access.
Solution
Edit /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f <PATH TO FILE> and set timestamp_timeout= to 15 minutes or less per your site policy. The value is in minutes. This entry may appear on its own or on the same line as other Defaults such as env_reset.
Example 1:
Defaults env_reset, timestamp_timeout=15
Example 2:
Defaults timestamp_timeout=15
Defaults env_reset
Note: On older sudo-rs releases the timestamp_timeout directive may be ignored. After applying the remediation on a sudo-rs target, run sudo -V and confirm the reported timeout matches expectations. If the value is not honored, upgrade sudo-rs to a release that supports timestamp_timeout or apply a compensating control via site policy.