| name | cis-ubuntu1604-v200-5-3-13 |
| description | Ensure SSH PermitUserEnvironment is disabled |
| category | cis-networking |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-16.04","ssh","remote-access"] |
| cis_id | 5.3.13 |
| cis_benchmark | CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - Control 5.3.13
Description
The PermitUserEnvironment option allows users to present environment options to the ssh daemon.
Rationale
Permitting users the ability to set environment variables through the SSH daemon could potentially allow users to bypass security controls (e.g. setting an execution path that has ssh executing a Trojan's programs).
Audit Procedure
Command Line
Run the following command and verify that output matches:
sshd -T -C user=root -C host="$(hostname)" -C addr="$(grep $(hostname) /etc/hosts | awk '{print $1}')" | grep permituserenvironment
Expected Result
permituserenvironment no
Run the following command and verify the output:
grep -Ei '^\s*PermitUserEnvironment\s+yes' /etc/ssh/sshd_config
Nothing should be returned.
Remediation
Command Line
Edit the /etc/ssh/sshd_config file to set the parameter as follows:
PermitUserEnvironment no
Default Value
PermitUserEnvironment no
References
- SSHD_CONFIG(5)
CIS Controls
Version 7
5.1 Establish Secure Configurations - Maintain documented, standard security configuration standards for all authorized operating systems and software.
Profile Applicability
- Level 1 - Server
- Level 1 - Workstation
Assessment Status
Automated