[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-55020-2

Platform: cpe:/o:redhat:enterprise_linux:8,cpe:/o:oracle:linux:7,cpe:/o:oracle:linux:8,cpe:/o:amazon:linux:2,cpe:/o:redhat:enterprise_linux:9,cpe:/o:redhat:enterprise_linux:7,cpe:/o:centos:centos:7Date: (C)2024-01-08   (M)2024-04-23



Sudo caches used credentials for a default of 15 minutes. This is for ease of use when there are multiple administrative tasks to perform. The timeout can be modified to suit local security policies. If the value is set to an integer less than 0, the user's time stamp will not expire and the user will not have to re-authenticate for privileged actions until the user's session is terminated.


Parameter:

[15]


Technical Mechanism:

Configure the sudo command to require re-authentication. Edit the /etc/sudoers file: Add or modify the following line: Defaults timestamp_timeout=[value] Note: The "[value]" must be a number that is greater than or equal to "0".

CCSS Severity:CCSS Metrics:
CCSS Score : 7.8Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97239
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97503
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:96250
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97472
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97208
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97439
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:97176


OVAL    7
oval:org.secpod.oval:def:97239
oval:org.secpod.oval:def:97439
oval:org.secpod.oval:def:96250
oval:org.secpod.oval:def:97503
...
XCCDF    7
xccdf_org.secpod_benchmark_general_RHEL_8
xccdf_org.secpod_benchmark_general_CENTOS_7
xccdf_org.secpod_benchmark_general_OEL_8
xccdf_org.secpod_benchmark_general_Amazon_Linux_2
...

© SecPod Technologies