1.6 Verify That 'MYSQL_PWD' Is Not Set In Users' Profiles

Information

MySQL can read a default database password from an environment variable called MYSQL_PWD.
NOTE : Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

Check which users and/or scripts are setting MYSQL_PWD and change them to use a more secure method.

See Also

https://workbench.cisecurity.org/files/1623