Skip to content

Conversation

@sysdig-aws-au-1
Copy link

Sysdig automated remediation for orders-db

Sysdig opened the pull request on behalf of Andrew Dean

Sysdig analysis found violations for resource orders-db

Remediated Control:

Container allowing privileged sub processes

A sub-process can gain more privileges than the parent process.

  • Severity: 🔴 High
  • Change Impact: The container will not be able to spawn new processes with privileged mode. All new process will have privileged set to false.

Failed Requirement:

  • 5.2.6 Minimize the admission of containers with allowPrivilegeEscalation [CIS Kubernetes V1.24 Benchmark]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant