Skip to content

Prisma Cloud Compute Defender containers must run as root.

An XCCDF Rule

Description

<VulnDiscussion>In certain situations, the nature of the vulnerability scanning may be more intrusive, or the container platform component that is the subject of the scanning may contain highly sensitive information. To protect the sensitive nature of such scanning, Prisma Cloud Compute Defenders perform the vulnerability scanning function. The Defender container must run as root and not privileged.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-253546r961563_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Redeploy the Defender with appropriate rights by setting Run Defenders as privileged = off. 

Delete old twistlock-defender-ds daemonSet and redeploy daemonSet with the new yaml.