aquasecurity / aquasecurity/docker-bench

id: 5.5 description: "Ensure sensitive host system directories are not mounted on containers Not effective

Open
#105 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
222
Forks
69
PR merge metrics
No merged PRs in 30d

Description

![image](https://user-images.githubusercontent.com/42887236/237037777-661c0616-bec6-49d2-9de9-73ca8ff736d9.png)
This is the container information when I mounted the/etc directory, but this detection passed. When I set the - flag: Source:/etc Destination in the rule
Set: false to - flag: Source:/etc
Set: false If you mount/etc again, it will be detected as not passing. I think there is a problem with the rule

Contributor guide

Open the contributing guide

Research direction

Start with the implementation of rule 5.5 and compare how it handles a container mounted with /etc against the suggested Source:/etc flag configuration. Reproduce the reported mount scenario and verify that the rule flags the container as not passing when the sensitive directory is mounted.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.