Skip to content

Conversation

sysdig-aws-au-1[bot]
Copy link

Sysdig opened the pull request on behalf of Andrew Dean.

Sysdig analysis found violations for workload "orders-db"

The PR includes remediations for the following attributes: "SecurityContext.AllowPrivilegeEscalation"


Remediated Attribute: "SecurityContext.AllowPrivilegeEscalation"
  • Severity: 🟢 None
  • Source:
    • Container: orders-db
  • Violated Control:
    • Container allowing privileged sub processes
      A sub-process can gain more privileges than the parent process.
  • Change Impact: The container will not be able to spawn new processes with privileged mode. All new process will have privileged set to false.

The following policy requirements applied to this resource include the above control:

Requirement Policy
5.2.6 Minimize the admission of containers with allowPrivilegeEscalation CIS Kubernetes V1.24 Benchmark

…egeEscalation" for control "Container allowing privileged sub processes"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants