Layer

Result

Comments

Nexus

os/lynis

PASS

No change since

Logs

os/vuls

FAIL:

141 unfixed vulnerabilities found

Most, if not all, of the vulnerabilities seem to come from the validation containers, not the host OS itself.

Change:

 :

152 unfixed vulnerabilities.

Total: 153 (High:33 Medium:93 Low:27 ?:0), 1/153 Fixed, 801 installed, 0 exploits, en: 2, ja: 0 alerts.

:

141 unfixed vulnerabilities.

Total: 153 (High:30 Medium:96 Low:27 ?:0), 12/153 Fixed, 795 installed, 0 exploits, en: 2, ja: 0 alerts

Logs

k8s/conformance

PASS

No change since

Logs

k8s/kubehunter

PASS except:

  • Inside-a-Pod Scanning: 1 vulnerability: CAP_NET_RAW

Patched system:public-info-viewer to hide /version and patched service account to disable automounting of service account tokens.

Change:

 :

Inside-a-Pod Scanning: 5 vulnerabilities.

:

Inside-a-Pod Scanning: 1 vulnerability: CAP_NET_RAW.

Logs
  • No labels