Skip to content

Sysdig - Remediate Workload :guestbook-ui#10

Open
sysdig-aws-us-2[bot] wants to merge 1 commit intomasterfrom
sysdig-remediate--guestbook-ui-1675360167
Open

Sysdig - Remediate Workload :guestbook-ui#10
sysdig-aws-us-2[bot] wants to merge 1 commit intomasterfrom
sysdig-remediate--guestbook-ui-1675360167

Conversation

@sysdig-aws-us-2
Copy link

Sysdig opened the pull request on behalf of Alex Wang.

Sysdig analysis found violations for workload "guestbook-ui"

The PR includes remediations for the following attributes: "SecurityContext.AllowPrivilegeEscalation"


Remediated Attribute: "SecurityContext.AllowPrivilegeEscalation"
  • Severity: 🔴 High
  • Source:
    • Container: guestbook-ui
  • Violated Control:
    • Container allowing privileged sub processes
      A sub-process can gain more privileges than the parent process.
  • Change Impact: The container will not be able to spawn new processes with privileged mode. All new process will have privileged set to false.

The following policy requirements applied to this resource include the above control:

Requirement Policy
4.2.5 Minimize the admission of containers with allowPrivilegeEscalation CIS Amazon Elastic Kubernetes Service (EKS) Benchmark
Kubernetes Controls All Findings

…alation" for control "Container allowing privileged sub processes"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants