Kubescape Scan Report


Summary:

All Failed Skipped
137 18 11

Details

Severity Control Name Failed Resources All Resources Risk Score, %
Critical CVE-2022-39328-grafana-auth-bypass 0 0 0
High Agent Sandbox claim override restrictions 0 0 0
High Agent Sandbox container resource limits 0 0 0
High Agent Sandbox egress policy enforcement 0 0 0
High Agent Sandbox hardened runtime class 0 0 0
High Agent Sandbox image provenance 0 0 0
High Agent Sandbox managed network policy 0 0 0
High Agent Sandbox resource ceilings 0 0 0
High Agent Sandbox service account token isolation 0 0 0
High Agent Sandbox strict egress policy 0 0 0
High Agent Substrate Worker Pod resource ceilings 0 0 0
High Agent runtime image digest pinning 0 0 0
High Agent runtime image registries 0 0 0
High Anonymous user has RoleBinding 0 0 0
High Applications credentials in configuration files 1 13 8
High Apply Security Context to Your Pods and Containers 12 12 100
High Avoid use of system:masters group 0 0 0
High CVE-2021-25742-nginx-ingress-snippet-annotation-vulnerability 0 0 0
High CVE-2022-47633-kyverno-signature-bypass 0 0 0
High Check if signature exists 12 12 100
High Configure Image Provenance using ImagePolicyWebhook admission controller 0 0 0
High Ensure CPU limits are set 0 12 0
High Ensure memory limits are set 0 12 0
High Forbidden Container Registries 0 12 0
High Host PID/IPC privileges 0 12 0
High HostNetwork access 0 12 0
High HostPath mount 0 12 0
High Ingress uses TLS 0 0 0
High Insecure capabilities 0 12 0
High List Kubernetes secrets 0 0 0
High Minimize the admission of Windows HostProcess Containers 0 0 0
High Minimize the admission of privileged containers 0 0 0
High Minimize wildcard use in Roles and ClusterRoles 0 0 0
High Privileged container 0 12 0
High Resource limits 0 12 0
High Resources CPU limit and request 0 12 0
High Resources memory limit and request 0 12 0
High ServiceAccount token mounted 0 2 0
High Verify image signature 0 12 0
High Workload with credential access 1 12 8
High Workload with secret access 0 14 0
High Workloads with Critical vulnerabilities exposed to external traffic 0 0 0
High Workloads with RCE vulnerabilities exposed to external traffic 0 0 0
High Writable hostPath mount 0 12 0
Medium Access container service account 0 0 0
Medium Administrative Roles 0 0 0
Medium Allow privilege escalation 0 12 0
Medium Automatic mapping of service account 0 18 0
Medium Bootstrap token authentication should not be used for users 0 0 0
Medium CVE-2022-24348-argocddirtraversal 0 0 0
Medium Client certificate authentication should not be used for users 0 0 0
Medium Cluster internal networking 0 0 0
Medium Configured liveness probe 1 12 8
Medium Container hostPort 0 12 0
Medium Container runtime socket mounted 0 12 0
Medium CoreDNS poisoning 0 0 0
Medium Dangling Gateway API backend 0 8 0
Medium Dangling HPA target 0 7 0
Medium Dangling Ingress backend 0 8 0
Medium Dangling NetworkPolicy 0 12 0
Medium Delete Kubernetes events 0 0 0
Medium Deprecated Kubernetes image registry 0 0 0
Medium Enable audit Logs 0 0 0
Medium Ensure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider 0 0 0
Medium Ensure that Service Account Tokens are only mounted where necessary 0 18 0
Medium Ensure that all Namespaces have Network Policies defined 0 0 0
Medium Ensure that default service accounts are not actively used 0 0 0
Medium Ensure that the cluster has at least one active policy control mechanism in place 0 0 0
Medium Ensure that the seccomp profile is set to docker/default in your pod definitions 2 12 17
Medium Images from allowed registry 0 12 0
Medium Ingress and Egress blocked 12 12 100
Medium Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster 0 0 0
Medium Linux hardening 2 12 17
Medium Minimize access to create persistent volumes 0 0 0
Medium Minimize access to create pods 0 0 0
Medium Minimize access to secrets 0 0 0
Medium Minimize access to the approval sub-resource of certificatesigningrequests objects 0 0 0
Medium Minimize access to the proxy sub-resource of nodes 0 0 0
Medium Minimize access to the service account token creation 0 0 0
Medium Minimize access to webhook configuration objects 0 0 0
Medium Minimize the admission of HostPath volumes 0 0 0
Medium Minimize the admission of containers which use HostPorts 0 0 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host IPC namespace 0 12 0
Medium Minimize the admission of containers wishing to share the host network namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host network namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 12 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 0 0
Medium Minimize the admission of containers wishing to share the host process ID namespace 0 0 0
Medium Minimize the admission of containers with added capabilities 0 0 0
Medium Minimize the admission of containers with added capabilities 0 0 0
Medium Minimize the admission of containers with allowPrivilegeEscalation 0 0 0
Medium Minimize the admission of containers with allowPrivilegeEscalation 0 0 0
Medium Minimize the admission of containers with capabilities assigned 0 0 0
Medium Minimize the admission of containers with capabilities assigned 0 0 0
Medium Minimize the admission of containers with the NET_RAW capability 0 0 0
Medium Minimize the admission of root containers 0 0 0
Medium Minimize the admission of root containers 0 0 0
Medium Missing network policy 12 13 92
Medium Mount service principal 0 12 0
Medium Nginx Ingress Controller End of Life 0 7 0
Medium No impersonation 0 0 0
Medium Non-existent service account 1 18 6
Medium Non-root containers 0 12 0
Medium Portforwarding privileges 0 0 0
Medium Prefer using secrets as files over secrets as environment variables 5 12 42
Medium Prevent containers from allowing command execution 0 0 0
Medium Restrict untrusted workloads 0 0 0
Medium Roles with delete capabilities 0 0 0
Medium Service account token authentication should not be used for users 0 0 0
Medium Sudo in container entrypoint 0 12 0
Medium Workload with ConfigMap access 1 13 8
Medium Workload with PVC access 0 13 0
Medium Workload with administrative roles 0 2 0
Medium Workload with cluster takeover roles 0 2 0
Medium Workloads with excessive amount of vulnerabilities 0 0 0
Low Access Kubernetes dashboard 0 12 0
Low Configured readiness probe 1 12 8
Low Deprecated serviceAccount field 0 12 0
Low Duplicate environment variable 0 12 0
Low Ensure CPU requests are set 0 12 0
Low Ensure memory requests are set 0 12 0
Low Image pull policy on latest tag 0 12 0
Low Images not pinned to digest 0 12 0
Low Immutable container filesystem 2 12 17
Low K8s common labels usage 0 12 0
Low Label usage for resources 12 12 100
Low Mismatching selector 0 7 0
Low Naked pods 4 4 100
Low Network mapping 0 0 0
Low No rolling update strategy 2 6 33
Low Outdated Kubernetes version 0 0 0
Low PSP enabled 0 0 0
Low Pods in default namespace 10 12 83
Low SSH server running inside container 0 0 0
Low Service with no workload 0 20 0

Failed Resources:


Name: -fhir-server-exporter-test-metrics-endpoint

ApiVersion: v1

Kind: Pod

Name: -fhir-server-exporter-test-metrics-endpoint

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-metrics-endpoint)

High Check if signature exists C-0237

spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-metrics-endpoint)

Medium Missing network policy C-0260

Name: -ohdsi-webapi

ApiVersion: apps/v1

Kind: Deployment

Name: -ohdsi-webapi

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[14].name (webapi)

spec.template.spec.containers[0].env[4].name (webapi)

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (webapi)

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: docker.io/ohdsi/webapi:2.15.2@sha256:bc5cffde0d6f29bccc994876bf3cb290e8c3f4e5c087ab28c7163343c0b67393) (webapi)

Medium Missing network policy C-0260

Name: -fhir-server-exporter

ApiVersion: apps/v1

Kind: Deployment

Name: -fhir-server-exporter

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (fhir-server-exporter)

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: ghcr.io/chgl/fhir-server-exporter:v3.0.19@sha256:26f8963a44d4e714c3413afad9afb3d9726f7ff6add1b755dda82145e5c03df9) (fhir-server-exporter)

Medium Missing network policy C-0260

Name: -magnifhir

ApiVersion: apps/v1

Kind: Deployment

Name: -magnifhir

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (magnifhir)

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: ghcr.io/chgl/magnifhir:v1.5.2@sha256:13f121613edd4e52051e864892fa532714c9ab935688c00fb9b772f502c413e9) (magnifhir)

Medium Missing network policy C-0260

Name: -minio

ApiVersion: apps/v1

Kind: Deployment

Name: -minio

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Medium Linux hardening C-0055

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (minio)

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[0].name (minio)

spec.template.spec.containers[0].env[1].name (minio)

Medium Ensure that the seccomp profile is set to docker/default in your pod definitions C-0210

spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault (minio)

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (minio)

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (minio)

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: docker.io/cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened@sha256:8dc02a7e509336c8bbb67962086d691bdcde20a2c9327ed68e5081a681f6dbfc) (minio)

Medium Missing network policy C-0260
Low No rolling update strategy C-0305

spec.strategy.type=RollingUpdate

spec.strategy.type (current: Recreate)

Name: -pathling-server-test-connection

ApiVersion: v1

Kind: Pod

Name: -pathling-server-test-connection

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-metadata-endpoint)

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-patient-endpoint)

spec.containers[2].securityContext.seLinuxOptions=YOUR_VALUE (probe-fhir-condition-count-endpoint)

spec.containers[3].securityContext.seLinuxOptions=YOUR_VALUE (probe-actuator-health-endpoint)

High Check if signature exists C-0237

spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-metadata-endpoint)

spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-patient-endpoint)

spec.containers[2].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-fhir-condition-count-endpoint)

spec.containers[3].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-actuator-health-endpoint)

Medium Missing network policy C-0260

Name: -ohdsi-atlas

ApiVersion: apps/v1

Kind: Deployment

Name: -ohdsi-atlas

Namespace:

Severity Name Docs Assisted Remediation
Low Immutable container filesystem C-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (atlas)

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (atlas)

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (atlas)

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: docker.io/ohdsi/atlas:2.15.0@sha256:6814e8c5b5366b50bc197b1eb2881689e5852784742b91b9636eec514f5a555e) (atlas)

Medium Missing network policy C-0260

Name: -postgres

ApiVersion: apps/v1

Kind: StatefulSet

Name: -postgres

Namespace:

Severity Name Docs Assisted Remediation
Low Immutable container filesystem C-0017

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (postgres)

Medium Ingress and Egress blocked C-0030
Medium Linux hardening C-0055

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (postgres)

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[3].name (postgres)

Medium Ensure that the seccomp profile is set to docker/default in your pod definitions C-0210

spec.template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault (postgres)

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.readOnlyRootFilesystem=true (postgres)

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (postgres)

spec.template.spec.containers[0].securityContext.seccompProfile=YOUR_VALUE (postgres)

spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: docker.io/postgres:18.4@sha256:d129b9577d274bb96cbd44d902bdeb1b935c89247d161241e9154cba64e13df4) (postgres)

Medium Workload with ConfigMap access C-0258

spec.template.spec.containers[0].volumeMounts[1] (postgres)

Medium Missing network policy C-0260

Name: -magnifhir-test

ApiVersion: v1

Kind: Pod

Name: -magnifhir-test

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (probe-web-endpoint)

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (probe-metrics-endpoint)

High Check if signature exists C-0237

spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-web-endpoint)

spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (probe-metrics-endpoint)

Medium Missing network policy C-0260

Name: -ohdsi-achilles-cron

ApiVersion: batch/v1beta1

Kind: CronJob

Name: -ohdsi-achilles-cron

Namespace:

Severity Name Docs Assisted Remediation
Low Configured readiness probe C-0018

spec.jobTemplate.spec.template.spec.containers[0].readinessProbe=YOUR_VALUE (achilles-cron)

Medium Ingress and Egress blocked C-0030
Medium Configured liveness probe C-0056

spec.jobTemplate.spec.template.spec.containers[0].livenessProbe=YOUR_VALUE (achilles-cron)

Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.jobTemplate.spec.template.metadata.labels[app]=YOUR_VALUE

Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.jobTemplate.spec.template.spec.containers[0].env[2].name (achilles-cron)

High Apply Security Context to Your Pods and Containers C-0211

spec.jobTemplate.spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (achilles-cron)

spec.jobTemplate.spec.template.spec.securityContext.fsGroupChangePolicy=Always

High Check if signature exists C-0237

spec.jobTemplate.spec.template.spec.containers[0].image (current: docker.io/ohdsi/broadsea-achilles:sha-bccd396@sha256:a881063aff6200d0d368ec30eb633381465fb8aa15e7d7138b7d48b6256a6feb) (achilles-cron)

Medium Missing network policy C-0260
Medium Non-existent service account C-0307

Name: -pathling-server

ApiVersion: apps/v1

Kind: Deployment

Name: -pathling-server

Namespace:

Severity Name Docs Assisted Remediation
High Applications credentials in configuration files C-0012

spec.template.spec.containers[0].env[3].name (pathling-server)

spec.template.spec.containers[0].env[3].value (pathling-server)

Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

spec.template.metadata.labels[app]=YOUR_VALUE

Medium Prefer using secrets as files over secrets as environment variables C-0207

spec.template.spec.containers[0].env[4].name (pathling-server)

spec.template.spec.containers[0].env[5].name (pathling-server)

spec.template.spec.initContainers[1].env[3].name (create-warehouse-bucket)

spec.template.spec.initContainers[1].env[4].name (create-warehouse-bucket)

High Apply Security Context to Your Pods and Containers C-0211

spec.template.spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (pathling-server)

High Check if signature exists C-0237

spec.template.spec.containers[0].image (current: ghcr.io/aehrc/pathling:3.0.0@sha256:463d11d0e757c6b838afbc6553fc726d2d46dd1eccd65bc37fd2b5da0f1f59eb) (pathling-server)

High Workload with credential access C-0259

spec.template.spec.containers[0].env[3].name (pathling-server)

spec.template.spec.containers[0].env[3].value (pathling-server)

Medium Missing network policy C-0260
Low No rolling update strategy C-0305

spec.strategy.type=RollingUpdate

spec.strategy.type (current: Recreate)

Name: -ohdsi-test-connection

ApiVersion: v1

Kind: Pod

Name: -ohdsi-test-connection

Namespace:

Severity Name Docs Assisted Remediation
Medium Ingress and Egress blocked C-0030
Low Pods in default namespace C-0061

metadata.namespace=YOUR_NAMESPACE

Low Naked pods C-0073
Low Label usage for resources C-0076

metadata.labels[app]=YOUR_VALUE

High Apply Security Context to Your Pods and Containers C-0211

spec.containers[0].securityContext.seLinuxOptions=YOUR_VALUE (test-webapi)

spec.containers[1].securityContext.seLinuxOptions=YOUR_VALUE (test-atlas)

High Check if signature exists C-0237

spec.containers[0].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (test-webapi)

spec.containers[1].image (current: docker.io/curlimages/curl:8.22.0@sha256:58adaa4e8dca9c988bae2aba4ab3434a0bb2da16bbe3f92dec39ec7785166777) (test-atlas)

Medium Missing network policy C-0260