UBTU-22-654224 - The operating system must restrict privilege elevation to authorized personnel.

Information

If the "sudoers" file is not configured correctly, any user defined on the system can initiate privileged actions on the target system.

Solution

Configure the operating system to restrict privilege elevation to authorized personnel.

Remove the following entries from the /etc/sudoers file or any configuration file under /etc/sudoers.d/:

ALL ALL=(ALL) ALL
ALL ALL=(ALL:ALL) ALL

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_22-04_LTS_V2R5_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-11, CAT|II, CCI|CCI-002038, CCI|CCI-004895, Rule-ID|SV-274861r1101704_rule, STIG-ID|UBTU-22-654224, Vuln-ID|V-274861

Plugin: Unix

Control ID: 59b99d529a40ef55eaa90bae577c022fe8dd87bbb167020b02c2ba7c275d898e