CCE-95467-7Platform: cpe:/o:amazon:linux:2, cpe:/o:centos:centos:7, cpe:/o:oracle:linux:7, cpe:/o:oracle:linux:8, cpe:/o:redhat:enterprise_linux:7, cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:enterprise_linux:9 | Date: (C)2021-03-05 (M)2023-07-04 |
Description:
sudo can use a custom log file
Rationale:
A sudo log file simplifies auditing of sudo commands
Audit:
Verify that sudo has a custom log file configured
Run the following command:
# grep -Ei ^s*Defaultss+([^#]+,s*)?logfile= /etc/sudoers
/etc/sudoers.d/*
Remediation:
edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following
line:
Defaults logfile=""
**Example
Defaults logfile="/var/log/sudo.log"
Impact:
editing the sudo configuration incorrectly can cause sudo to stop functioning
Parameter:
[/var/log/sudo.log]
Technical Mechanism:
edit the file /etc/sudoers or a file in /etc/sudoers.d/ with visudo -f and add the following
line:
Defaults logfile=" PATH TO CUSTOM LOG FILE "
**Example
Defaults logfile="/var/log/sudo.log"
CCSS Severity: | CCSS Metrics: |
CCSS Score : 6.8 | Attack Vector: LOCAL |
Exploit Score: 2.5 | Attack Complexity: LOW |
Impact Score: 3.7 | Privileges Required: NONE |
Severity: MEDIUM | User Interaction: NONE |
Vector: AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L | Scope: CHANGED |
| Confidentiality: LOW |
| Integrity: LOW |
| Availability: LOW |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:72377 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:68618 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:73018 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:72913 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:84251 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:72704 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:72807 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:72011 |