Pod Base image Your applications Pod Deployment Replication Controller アプリケーションに含まれてい る脆弱性 Kubernetes により増幅・露出 された脆弱性 App dependencies Kubernetes=脆弱性 増幅システム?
details Get parent of workload Send workload metadata Store metadata Pull image Scan image Send scan result Store scan results Running on your cluster Controller
announced Kubernetes context Not setting a read only root filesystem where the CWE indicates filesystem access is required. Permission issues (for instance running privileged, able to run as root, not dropping capabilities) and a CVSSv3 Privileges (PR) vector present in the vulnerability.