Kubescape Scan Report


Summary:

All Failed Skipped
118 14 10

Details

Severity Control Name Failed Resources All Resources Risk Score, %
Critical CVE-2022-39328-grafana-auth-bypass 0 0 0
High Anonymous user has RoleBinding 0 0 0
High Applications credentials in configuration files 1 14 7
High Apply Security Context to Your Pods and Containers 13 13 100
High Avoid use of system:masters group 0 0 0
High CVE-2021-25742-nginx-ingress-snippet-annotation-vulnerability 0 0 0
High CVE-2022-47633-kyverno-signature-bypass 0 0 0
High Check if signature exists 13 13 100
High Configure Image Provenance using ImagePolicyWebhook admission controller 0 0 0
High Ensure CPU limits are set 0 13 0
High Ensure memory limits are set 0 13 0
High Forbidden Container Registries 0 13 0
High Host PID/IPC privileges 0 13 0
High HostNetwork access 0 13 0
High HostPath mount 0 13 0
High Ingress uses TLS 0 0 0
High Insecure capabilities 0 13 0
High List Kubernetes secrets 0 0 0
High Minimize the admission of Windows HostProcess Containers 0 0 0
High Minimize the admission of privileged containers 0 0 0
High Minimize wildcard use in Roles and ClusterRoles 0 0 0
High Privileged container 0 13 0
High Resource limits 0 13 0
High Resources CPU limit and request 0 13 0
High Resources memory limit and request 0 13 0
High ServiceAccount token mounted 0 2 0
High Verify image signature 0 13 0
High Workload with credential access 1 13 8
High Workload with secret access 0 15 0
High Workloads with Critical vulnerabilities exposed to external traffic 0 0 0
High Workloads with RCE vulnerabilities exposed to external traffic 0 0 0
High Writable hostPath mount 0 13 0
Medium Access container service account 0 0 0
Medium Administrative Roles 0 0 0
Medium Allow privilege escalation 0 13 0
Medium Automatic mapping of service account 0 20 0
Medium Bootstrap token authentication should not be used for users 0 0 0
Medium CVE-2022-24348-argocddirtraversal 0 0 0
Medium Client certificate authentication should not be used for users 0 0 0
Medium Cluster internal networking 0 0 0
Medium Configured liveness probe 0 13 0
Medium Container hostPort 0 13 0
Medium Container runtime socket mounted 0 13 0
Medium CoreDNS poisoning 0 0 0
Medium Delete Kubernetes events 0 0 0
Medium Deprecated Kubernetes image registry 0 0 0
Medium Enable audit Logs 0 0 0
Medium Ensure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider 0 0 0
Medium Ensure that Service Account Tokens are only mounted where necessary 0 20 0
Medium Ensure that all Namespaces have Network Policies defined 0 0 0
Medium Ensure that default service accounts are not actively used 0 0 0
Medium Ensure that the cluster has at least one active policy control mechanism in place 0 0 0
Medium Ensure that the seccomp profile is set to docker/default in your pod definitions 2 13 15
Medium Images from allowed registry 0 13 0
Medium Ingress and Egress blocked 13 13 100
Medium Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster 0 0 0
Medium Linux hardening 2 13 15
Medium Minimize access to create persistent volumes 0 0 0
Medium Minimize access to create pods 0 0 0
Medium Minimize access to secrets 0 0 0
Medium Minimize access to the approval sub-resource of certificatesigningrequests objects 0 0 0
Medium Minimize access to the proxy sub-resource of nodes 0 0 0
Medium Minimize access to the service account token creation 0 0 0
Medium Minimize access to webhook configuration objects 0 0 0
Medium Minimize the admission of HostPath volumes 0 0 0
Medium Minimize the admission of containers which use HostPorts 0 0 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 13 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host network namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host network namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 13 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 0 0
Medium Minimize the admission of containers with added capabilities 0 0 0
Medium Minimize the admission of containers with added capabilities 0 0 0
Medium Minimize the admission of containers with allowPrivilegeEscalation 0 0 0
Medium Minimize the admission of containers with allowPrivilegeEscalation 0 0 0
Medium Minimize the admission of containers with capabilities assigned 0 0 0
Medium Minimize the admission of containers with capabilities assigned 0 0 0
Medium Minimize the admission of containers with the NET_RAW capability 0 0 0
Medium Minimize the admission of root containers 0 0 0
Medium Minimize the admission of root containers 0 0 0
Medium Missing network policy 13 14 93
Medium Mount service principal 0 13 0
Medium Nginx Ingress Controller End of Life 0 8 0
Medium No impersonation 0 0 0
Medium Non-root containers 0 13 0
Medium Portforwarding privileges 0 0 0
Medium Prefer using secrets as files over secrets as environment variables 5 13 38
Medium Prevent containers from allowing command execution 0 0 0
Medium Restrict untrusted workloads 0 0 0
Medium Roles with delete capabilities 0 0 0
Medium Service account token authentication should not be used for users 0 0 0
Medium Sudo in container entrypoint 0 13 0
Medium Workload with ConfigMap access 1 14 7
Medium Workload with PVC access 0 14 0
Medium Workload with administrative roles 0 2 0
Medium Workload with cluster takeover roles 0 2 0
Medium Workloads with excessive amount of vulnerabilities 0 0 0
Low Access Kubernetes dashboard 0 13 0
Low Configured readiness probe 0 13 0
Low Deprecated serviceAccount field 0 13 0
Low Duplicate environment variable 0 13 0
Low Ensure CPU requests are set 0 13 0
Low Ensure memory requests are set 0 13 0
Low Image pull policy on latest tag 0 13 0
Low Immutable container filesystem 2 13 15
Low K8s common labels usage 0 13 0
Low Label usage for resources 13 13 100
Low Mismatching selector 0 8 0
Low Naked pods 5 5 100
Low Network mapping 0 0 0
Low Outdated Kubernetes version 0 0 0
Low PSP enabled 0 0 0
Low Pods in default namespace 11 13 85
Low SSH server running inside container 0 0 0
Low Service with no workload 0 22 0

Failed Resources:


Name: -pathling-server-test-connection

ApiVersion: v1

Kind: Pod

Name: -pathling-server-test-connection

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.containers[0].image

spec.containers[1].image

spec.containers[2].image

spec.containers[3].image

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[3].securityContext.seLinuxOptions=YOUR_VALUE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -magnifhir-test

ApiVersion: v1

Kind: Pod

Name: -magnifhir-test

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.containers[0].image

spec.containers[1].image

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -fhir-server-exporter

ApiVersion: apps/v1

Kind: Deployment

Name: -fhir-server-exporter

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -fhir-server-test-connection

ApiVersion: v1

Kind: Pod

Name: -fhir-server-test-connection

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.containers[0].image

spec.containers[1].image

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -ohdsi-test-connection

ApiVersion: v1

Kind: Pod

Name: -ohdsi-test-connection

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.containers[0].image

spec.containers[1].image

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -fhir-server

ApiVersion: apps/v1

Kind: Deployment

Name: -fhir-server

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[10].name

spec.template.spec.containers[0].env[11].name

spec.template.spec.containers[0].env[9].name

High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -minio

ApiVersion: apps/v1

Kind: Deployment

Name: -minio

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[0].name

spec.template.spec.containers[0].env[1].name

High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Medium Ensure that the seccomp profile is set to docker/default in your pod definitions C-0210

spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault

Medium Linux hardening C-0055

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE

Name: -ohdsi-atlas

ApiVersion: apps/v1

Kind: Deployment

Name: -ohdsi-atlas

Namespace:

Severity Name Docs Assisted Remediation
Low Immutable container filesystem C-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -postgres

ApiVersion: apps/v1

Kind: StatefulSet

Name: -postgres

Namespace:

Severity Name Docs Assisted Remediation
Low Immutable container filesystem C-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

Medium Missing network policy C-0260
Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name

High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Medium Ensure that the seccomp profile is set to docker/default in your pod definitions C-0210

spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault

Medium Workload with ConfigMap access C-0258

spec.template.spec.containers[0].volumeMounts[1]

Medium Linux hardening C-0055

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE

Name: -magnifhir

ApiVersion: apps/v1

Kind: Deployment

Name: -magnifhir

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -ohdsi-webapi

ApiVersion: apps/v1

Kind: Deployment

Name: -ohdsi-webapi

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[14].name

spec.template.spec.containers[0].env[4].name

High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -pathling-server

ApiVersion: apps/v1

Kind: Deployment

Name: -pathling-server

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name

spec.template.spec.containers[0].env[5].name

High Check if signature exists C-0237

spec.template.spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Workload with credential access C-0259

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[3].value

High Applications credentials in configuration files C-0012

spec.template.spec.containers[0].env[3].name

spec.template.spec.containers[0].env[3].value

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Name: -fhir-server-exporter-test-metrics-endpoint

ApiVersion: v1

Kind: Pod

Name: -fhir-server-exporter-test-metrics-endpoint

Namespace:

Severity Name Docs Assisted Remediation
Medium Missing network policy C-0260
High Check if signature exists C-0237

spec.containers[0].image

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE