Skip to content

Commit

Permalink
Merge pull request #9932 from rumch-se/package_rsync_removed
Browse files Browse the repository at this point in the history
Added a new SLE 12/15 rule package_rsync_removed
  • Loading branch information
anivan-suse authored Dec 13, 2022
2 parents 76356e5 + df16405 commit bcf5237
Show file tree
Hide file tree
Showing 5 changed files with 36 additions and 8 deletions.
5 changes: 2 additions & 3 deletions controls/cis_sle12.yml
Original file line number Diff line number Diff line change
Expand Up @@ -732,11 +732,10 @@ controls:
levels:
- l1_server
- l1_workstation
automated: partially
notes: >-
Package removal not covered by this rule
status: automated
rules:
- service_rsyncd_disabled
- package_rsync_removed

- id: 2.2.18
title: Ensure NIS server is not installed (Automated)
Expand Down
5 changes: 2 additions & 3 deletions controls/cis_sle15.yml
Original file line number Diff line number Diff line change
Expand Up @@ -713,11 +713,10 @@ controls:
levels:
- l1_server
- l1_workstation
automated: partially
notes: >-
Package removal not covered by this rule
status: automated
rules:
- service_rsyncd_disabled
- package_rsync_removed

- id: 2.2.18
title: Ensure NIS server is not installed (Automated)
Expand Down
32 changes: 32 additions & 0 deletions linux_os/guide/services/obsolete/package_rsync_removed/rule.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
documentation_complete: true

prodtype: sle12,sle15

title: 'Uninstall rsync Package'

description: |-
The rsyncd service can be used to synchronize files between systems over network links.
{{{ describe_package_remove(package="rsync") }}}
rationale: |-
The rsyncd service presents a security risk as it uses unencrypted protocols for
communication.
severity: medium

identifiers:
cce@sle12: CCE-92313-6
cce@sle15: CCE-92468-8

references:
cis@sle12: 2.2.17
cis@sle15: 2.2.17

{{{ complete_ocil_entry_package(package="rsync") }}}

fixtext: '{{{ fixtext_package_removed("rsync") }}}'

template:
name: package_removed
vars:
pkgname: rsync
1 change: 0 additions & 1 deletion shared/references/cce-sle12-avail.txt
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,6 @@ CCE-92308-6
CCE-92310-2
CCE-92311-0
CCE-92312-8
CCE-92313-6
CCE-92314-4
CCE-92318-5
CCE-92319-3
Expand Down
1 change: 0 additions & 1 deletion shared/references/cce-sle15-avail.txt
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,6 @@ CCE-92464-7
CCE-92465-4
CCE-92466-2
CCE-92467-0
CCE-92468-8
CCE-92469-6
CCE-92470-4
CCE-92472-0
Expand Down

0 comments on commit bcf5237

Please sign in to comment.