AVD-KSV-0118 false positive (pod X using the default security context, which allows root privileges) #9326
Closed
huornlmj
started this conversation in
False Detection
Replies: 1 comment
-
|
thanks @huornlmj - this looks like a bug to me in the check. Track #9329 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
AVD-KSV-0118
Description
The following section of a K8s manifest file is throwing AVD-KSV-0118 which is a false positive in this scenario.
Output:
K8s manifest file spec and securityContext section:
Reproduction Steps
1. Scan https://github.com/intel/intent-driven-orchestration/blob/9f37fe0552245f1c8b41285aed61696c3b375ceb/artefacts/deploy/manifest.yaml 2. Observe the false positive appear repeatedly.Target
Kubernetes
Scanner
Misconfiguration
Target OS
N/A
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions