Amazon Linux 2023 must require reauthentication when using the "sudo" command.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| medium | V-274014 | SRG-OS-000373-GPOS-00157 | AZLX-23-001010 | SV-274014r1120030_rule | 2025-07-15 | 1 |
| Description |
|---|
| Without reauthentication, users may access resources or perform tasks for which they do not have authorization. |
| ℹ️ Check |
|---|
| Verify Amazon Linux 2023 requires reauthentication when using the "sudo" command to elevate privileges with the following command: $ sudo grep -ir 'timestamp_timeout' /etc/sudoers /etc/sudoers.d/ /etc/sudoers:Defaults timestamp_timeout=0 If results are returned from more than one file location, this is a finding. If "timestamp_timeout" is set to a negative number, is commented out, or no results are returned, this is a finding. |
| ✔️ Fix |
|---|
| Configure Amazon Linux 2023 to reauthenticate "sudo" commands after the specified timeout: Add the following line to "/etc/sudoers" or a file in "/etc/sudoers.d": Defaults timestamp_timeout=0 |