Skip to content

The container platform runtime must enforce the use of ports that are non-privileged.

An XCCDF Rule

Description

Privileged ports are those ports below 1024 and that require system privileges for their use. If containers are able to use these ports, the container must be run as a privileged user. The container platform must stop containers that try to map to these ports directly. Allowing non-privileged ports to be mapped to the container-privileged port is the allowable method when a certain port is needed. An example is mapping port 8080 externally to port 80 in the container.

ID
SV-233074r1043177_rule
Version
SRG-APP-000142-CTR-000330
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the container platform to disallow the use of privileged ports by containers. Move any containers that are using privileged ports to non-privileged ports.