SV-230318r1155352_rule
V-230318
SRG-OS-000480-GPOS-00227
RHEL-08-010700
CAT II
10
Configure all RHEL 8 public directories to be owned by root or a system account to prevent unauthorized and unintended information transferred via shared system resources.
Use the following command template to set ownership of public directories to root or a system account:
$ sudo chown [root or system account] [Public Directory]
Verify RHEL 8 world writable directories are owned by root, a system account, or an application account with the following command:
$ sudo find / -xdev -type d -perm -0002 -uid +999 -exec stat -c "%U, %u, %A, %n" {} \; 2>/dev/null
If there is output that indicates world-writable directories are owned by any account other than root or an approved system account, this is a finding.
V-230318
False
RHEL-08-010700
Verify RHEL 8 world writable directories are owned by root, a system account, or an application account with the following command:
$ sudo find / -xdev -type d -perm -0002 -uid +999 -exec stat -c "%U, %u, %A, %n" {} \; 2>/dev/null
If there is output that indicates world-writable directories are owned by any account other than root or an approved system account, this is a finding.
M
2921