RHEL 9 must not be configured to bypass password requirements for privilege escalation.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-258118
RHEL-09-611145
SV-258118r1050789_rule
Medium
Description
Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to escalate a functional capability, it is critical the user reauthenticate.
Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158