|
|
d10e36 |
diff --git a/controls/anssi.yml b/controls/anssi.yml
|
|
|
d10e36 |
index 851993512..515a4a172 100644
|
|
|
d10e36 |
--- a/controls/anssi.yml
|
|
|
d10e36 |
+++ b/controls/anssi.yml
|
|
|
d10e36 |
@@ -850,7 +850,8 @@ controls:
|
|
|
d10e36 |
- id: R63
|
|
|
d10e36 |
level: intermediary
|
|
|
d10e36 |
title: Explicit arguments in sudo specifications
|
|
|
d10e36 |
- # rules: TBD
|
|
|
d10e36 |
+ rules:
|
|
|
d10e36 |
+ - sudoers_explicit_command_args
|
|
|
d10e36 |
|
|
|
d10e36 |
- id: R64
|
|
|
d10e36 |
level: intermediary
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/oval/shared.xml b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/oval/shared.xml
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..94a0cb421
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/oval/shared.xml
|
|
|
d10e36 |
@@ -0,0 +1,25 @@
|
|
|
d10e36 |
+<def-group>
|
|
|
d10e36 |
+ <definition class="compliance" id="{{{ rule_id }}}" version="1">
|
|
|
d10e36 |
+ {{{ oval_metadata("Check that sudoers doesn't contain commands without arguments specified") }}}
|
|
|
d10e36 |
+ <criteria operator="AND">
|
|
|
d10e36 |
+ <criterion comment="Make sure that no commands are without arguments" test_ref="test_{{{ rule_id }}}" />
|
|
|
d10e36 |
+ </criteria>
|
|
|
d10e36 |
+ </definition>
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ comment="Make sure that no command in user spec is without any argument"
|
|
|
d10e36 |
+ id="test_{{{ rule_id }}}" version="1">
|
|
|
d10e36 |
+ <ind:object object_ref="object_{{{ rule_id }}}" />
|
|
|
d10e36 |
+ </ind:textfilecontent54_test>
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ <ind:textfilecontent54_object id="object_{{{ rule_id }}}" version="1">
|
|
|
d10e36 |
+ <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ where a command is <runas spec>?<anything except ,>+,
|
|
|
d10e36 |
+ - ',' is a command delimiter, while
|
|
|
d10e36 |
+ The last capturing group holds the offending command without args.
|
|
|
d10e36 |
+ -->
|
|
|
d10e36 |
+ <ind:pattern operation="pattern match">^(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+(?:[ \t]+[^,\s]+)+[ \t]*,)*(\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+[ \t]*(?:,|$))</ind:pattern>
|
|
|
d10e36 |
+ <ind:instance datatype="int">1</ind:instance>
|
|
|
d10e36 |
+ </ind:textfilecontent54_object>
|
|
|
d10e36 |
+</def-group>
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/rule.yml b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/rule.yml
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..a0590c8b0
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/rule.yml
|
|
|
d10e36 |
@@ -0,0 +1,46 @@
|
|
|
d10e36 |
+documentation_complete: true
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+title: "Explicit arguments in sudo specifications"
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+description: |-
|
|
|
d10e36 |
+ All commands in the sudoers file must strictly specify the arguments allowed to be used for a given user.
|
|
|
d10e36 |
+ If the command is supposed to be executed only without arguments, pass "" as an argument in the corresponding user specification.
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+rationale: |-
|
|
|
d10e36 |
+ Any argument can modify quite significantly the behavior of a program, whether regarding the
|
|
|
d10e36 |
+ realized operation (read, write, delete, etc.) or accessed resources (path in a file system tree). To
|
|
|
d10e36 |
+ avoid any possibility of misuse of a command by a user, the ambiguities must be removed at the
|
|
|
d10e36 |
+ level of its specification.
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ For example, on some systems, the kernel messages are only accessible by root.
|
|
|
d10e36 |
+ If a user nevertheless must have the privileges to read them, the argument of the dmesg command has to be restricted
|
|
|
d10e36 |
+ in order to prevent the user from flushing the buffer through the -c option:
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ user ALL = dmesg ""
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+severity: medium
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+identifiers:
|
|
|
d10e36 |
+ cce@rhel7: CCE-83631-2
|
|
|
d10e36 |
+ cce@rhel8: CCE-83632-0
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+references:
|
|
|
d10e36 |
+ anssi: BP28(R63)
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ocil_clause: '/etc/sudoers file contains user specifications that allow execution of commands with any arguments'
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ocil: |-
|
|
|
d10e36 |
+ To determine if arguments that commands can be executed with are restricted, run the following command:
|
|
|
d10e36 |
+ $ sudo grep -PR '^(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+(?:[ \t]+[^,\s]+)+[ \t]*,)*(\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+[ \t]*(?:,|$))' /etc/sudoers /etc/sudoers.d/
|
|
|
d10e36 |
+ The command should return no output.
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+platform: sudo
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+warnings:
|
|
|
d10e36 |
+ - general:
|
|
|
d10e36 |
+ This rule doesn't come with a remediation, as absence of arguments in the user spec doesn't mean that the command is intended to be executed with no arguments.
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+ - general:
|
|
|
d10e36 |
+ The rule can produce false findings when an argument contains a comma - sudoers syntax allows comma escaping using backslash, but the check doesn't support that.
|
|
|
d10e36 |
+ For example, root ALL=(ALL) echo 1\,2 allows root to execute echo 1,2 , but the check would interpret it as two commands echo 1\ and 2 .
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/commented.pass.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/commented.pass.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..b0d05b2a5
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/commented.pass.sh
|
|
|
d10e36 |
@@ -0,0 +1,5 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo '#jen,!fred ALL, !SERVERS = !/bin/sh' > /etc/sudoers
|
|
|
d10e36 |
+echo '# somebody ALL=/bin/ls, (!bob,alice) !/bin/cat, /bin/dog' > /etc/sudoers.d/foo
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-1.fail.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-1.fail.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..c6f885f9f
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-1.fail.sh
|
|
|
d10e36 |
@@ -0,0 +1,5 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+# remediation = none
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'somebody ALL=/bin/ls, (!bob,alice) /bin/cat arg, /bin/dog' > /etc/sudoers
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-2.fail.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-2.fail.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..fce851f55
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/complex-2.fail.sh
|
|
|
d10e36 |
@@ -0,0 +1,5 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+# remediation = none
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls, (!bob,alice) /bin/dog, /bin/cat arg' > /etc/sudoers
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/false_positive.fail.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/false_positive.fail.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..baf66468d
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/false_positive.fail.sh
|
|
|
d10e36 |
@@ -0,0 +1,9 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# remediation = none
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+# The val1\,val2 is the first argument of the /bin/dog command that contains a comma.
|
|
|
d10e36 |
+# Our check tends to interpret the comma as commad delimiter, so the dog arg is val1\
|
|
|
d10e36 |
+# and val2 is another command in the user spec.
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls "", (!bob,alice) /bin/dog val1\,val2, /bin/cat ""' > /etc/sudoers
|
|
|
d10e36 |
+
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.fail.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.fail.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..9a04a205a
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.fail.sh
|
|
|
d10e36 |
@@ -0,0 +1,5 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+# remediation = none
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'jen,!fred ALL,SERVERS = /bin/sh ' > /etc/sudoers
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.pass.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.pass.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..4a3a7c94b
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/simple.pass.sh
|
|
|
d10e36 |
@@ -0,0 +1,6 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls "", (!bob,alice) /bin/dog arg, /bin/cat ""' > /etc/sudoers
|
|
|
d10e36 |
+echo 'jen,!fred ALL,!SERVERS = /bin/sh arg' >> /etc/sudoers
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls arg arg, (bob,!alice) /bin/dog arg, /bin/cat arg' > /etc/sudoers.d/foo
|
|
|
d10e36 |
diff --git a/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/sudoers_d.fail.sh b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/sudoers_d.fail.sh
|
|
|
d10e36 |
new file mode 100644
|
|
|
d10e36 |
index 000000000..9643a3337
|
|
|
d10e36 |
--- /dev/null
|
|
|
d10e36 |
+++ b/linux_os/guide/system/software/sudo/sudoers_explicit_command_args/tests/sudoers_d.fail.sh
|
|
|
d10e36 |
@@ -0,0 +1,9 @@
|
|
|
d10e36 |
+# platform = multi_platform_all
|
|
|
d10e36 |
+# packages = sudo
|
|
|
d10e36 |
+# remediation = none
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls, (!bob,alice) /bin/dog arg, /bin/cat ""' > /etc/sudoers
|
|
|
d10e36 |
+echo 'jen,!fred ALL,!SERVERS = /bin/sh arg' >> /etc/sudoers
|
|
|
d10e36 |
+echo 'nobody ALL=/bin/ls, (bob,!alice) /bin/dog arg, /bin/cat arg' > /etc/sudoers.d/foo
|
|
|
d10e36 |
+
|
|
|
d10e36 |
+echo 'user ALL = ALL' > /etc/sudoers.d/bar
|
|
|
d10e36 |
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
|
|
|
d10e36 |
index 4dbec8255..94a116b59 100644
|
|
|
d10e36 |
--- a/shared/references/cce-redhat-avail.txt
|
|
|
d10e36 |
+++ b/shared/references/cce-redhat-avail.txt
|
|
|
d10e36 |
@@ -140,8 +140,6 @@ CCE-83626-2
|
|
|
d10e36 |
CCE-83627-0
|
|
|
d10e36 |
CCE-83628-8
|
|
|
d10e36 |
CCE-83629-6
|
|
|
d10e36 |
-CCE-83631-2
|
|
|
d10e36 |
-CCE-83632-0
|
|
|
d10e36 |
CCE-83633-8
|
|
|
d10e36 |
CCE-83634-6
|
|
|
d10e36 |
CCE-83635-3
|