RHEL 9 must require users to reauthenticate for privilege escalation.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-258086
RHEL-09-432025
SV-258086r1050789_rule
Medium
Description
Without reauthentication, users may access resources or perform tasks for which they do not have authorization.
When operating systems provide the capability to escalate a functional capability, it is critical that the user reauthenticate.
Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158