Amazon Linux 2023 must have the sudo package installed.

STIG ID: AZLX-23-001000  |  SRG: SRG-OS-000324-GPOS-00125 |  Severity: medium (CAT II)  |  CCI: CCI-002235 |  Vulnerability Id: V-274012

Vulnerability Discussion

The "sudo" program is designed to allow a system administrator to give limited root privileges to users and log root activity. The basic philosophy is to give as few privileges as possible but still allow system users to get their work done.

Check

Verify Amazon Linux 2023 has the sudo package installed with the following command:

$ dnf list --installed sudo
Installed Packages
sudo.x86_64 1.9.15-1.p5.amzn2023.0.1 @System

If the "sudo" package is not installed, this is a finding.

Fix

Configure Amazon Linux 2023 to have the sudo package installed with the following command:

$ sudo dnf install -y sudo