1.1.9 Is checking the wrong file
@konstruktoid ya está trabajando en esto.
Desde el 4/6/2024.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
The definition of 1.1.9 in the published CIS Docker Benchmarks is ambiguous.
Steps 1 & 2 locate the actual socket, then step 3 checks that the systemctl file is being audited (with the remediation being to audit the actual socket).
I think that both the systemctl file (/lib/systemd/system/docker.socket) and the actual socket (/var/run/docker.sock) should be audited.
The updated version of the CIS Benchmarks (available within CIS WorkBench) is now unampbiguously about the socket itself (/var/run/docker.sock).
- Lenguaje dominante
- Shell
- Estrellas
- 9.7k
- Forks
- 1k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de docker/docker-bench-security
-
[Bug] Test `check_1_1_5` uses a hard-coded path for Docker data rootQuizá libre de nuevo @thaJeztah la tomó hace 310 días y no hay ningún pull request abierto. Abierto
docker/docker-bench-security#577 · 1 asignado ·
-
docker/docker-bench-security#573 · 1 comentario · 1 asignado ·
-
name: ciQuizá libre de nuevo @thaJeztah la tomó hace 321 días y no hay ningún pull request abierto. Abierto
docker/docker-bench-security#571 · 1 asignado ·
-
[Bug] 1.1.5 doesn't take into account a changed data-rootQuizá libre de nuevo @konstruktoid la tomó hace 601 días y no hay ningún pull request abierto. Abierto
docker/docker-bench-security#568 · 2 comentarios · 1 asignado ·
-
[Typo] 2.18 doesn't report ID in outputQuizá libre de nuevo @konstruktoid la tomó hace 606 días y no hay ningún pull request abierto. Abierto
docker/docker-bench-security#567 · 1 asignado ·
Todos los issues de docker/docker-bench-security
Issues similares
-
package-update
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
bug needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
obra/superpowers#2394 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
CachyOS/cachyos-aur-derived#772 ·
Los mantenedores suelen responder en 1 día
-
documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
kristofdegrave/homeassistant-smart-charging#1413 ·
Los mantenedores suelen responder en 1 día