[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50131-2

Platform: cpe:/o:apple:mac_os_13Date: (C)2024-04-17   (M)2024-04-17



With macOS 10.12, Apple introduced the capability to have a user's Desktop and Documents folders automatically synchronize to the user's iCloud Drive, provided they have enough room purchased through Apple on their iCloud Drive. This capability mirrors what Microsoft is doing with the use of OneDrive and Office 365. There are concerns with using this capability. The storage space that Apple provides for free is used by users with iCloud mail, all of a user's Photo Library created with the ever larger Multi-Pixel iPhone cameras, and all iOS Backups. Adding a synchronization capability for users who have files going back a decade or more, storage may be tight using the free 5GB provided without purchasing much larger storage capacity from Apple. Rationale: Automated Document synchronization should be planned and controlled to approved storage. Impact: Users will not be able to use iCloud for the automatic sync of the Desktop and Documents folders. Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.applicationaccess 2. The key to include is allowCloudDesktopAndDocuments 3. The key must be set to <false/>


Parameter:

[Yes/No]


Technical Mechanism:

Remediation: Profile Method: Create or edit a configuration profile with the following information: 1. The PayloadType string is com.apple.applicationaccess 2. The key to include is allowCloudDesktopAndDocuments 3. The key must be set to false/

CCSS Severity:CCSS Metrics:
CCSS Score : 5.3Attack Vector: NETWORK
Exploit Score: 3.9Attack Complexity: LOW
Impact Score: 1.4Privileges Required: NONE
Severity: MEDIUMUser Interaction: NONE
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LScope: UNCHANGED
 Confidentiality: NONE
 Integrity: NONE
 Availability: LOW
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99083


OVAL    1
oval:org.secpod.oval:def:99083
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_13

© SecPod Technologies