Closed qiangxuhui closed 10 months ago
code | level | alerts | |
---|---|---|---|
0 | CIS-DI-0009 | FATAL | Use COPY : /bin/sh -c #(nop) ADD file:d6033f939d5ff5ce1b27e670b84ba50af2dc70488610485fcc6d9a90cae22d18 in bin/docker-startup.sh |
1 | CIS-DI-0010 | FATAL | Suspicious ENV key found : TOMCAT_ACCESSLOG_ENABLED on /bin/sh -c #(nop) ENV MODE=cluster PREFER_HOST_MODE=ip BASE_DIR=/home/nacos CLASSPATH=.:/home/nacos/conf: CLUSTER_CONF=/home/nacos/conf/cluster.conf FUNCTION_MODE=all JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk NACOS_USER=nacos JAVA=/usr/lib/jvm/java-1.8.0-openjdk/bin/java JVM_XMS=1g JVM_XMX=1g JVM_XMN=512m JVM_MS=128m JVM_MMS=320m NACOS_DEBUG=n TOMCAT_ACCESSLOG_ENABLED=false TIME_ZONE=Asia/Shanghai (You can suppress it with --accept-key) |
2 | CIS-DI-0001 | WARN | Last user should not be root |
3 | CIS-DI-0005 | INFO | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
4 | CIS-DI-0006 | INFO | not found HEALTHCHECK statement |
5 | CIS-DI-0008 | INFO | setuid file: urwxr-xr-x usr/bin/gpasswd |
code | level | alerts | |
---|---|---|---|
0 | CIS-DI-0009 | FATAL | Use COPY : /bin/sh -c #(nop) ADD file:d6033f939d5ff5ce1b27e670b84ba50af2dc70488610485fcc6d9a90cae22d18 in bin/docker-startup.sh |
1 | CIS-DI-0010 | FATAL | Suspicious ENV key found : TOMCAT_ACCESSLOG_ENABLED on /bin/sh -c #(nop) ENV MODE=cluster PREFER_HOST_MODE=ip BASE_DIR=/home/nacos CLASSPATH=.:/home/nacos/conf: CLUSTER_CONF=/home/nacos/conf/cluster.conf FUNCTION_MODE=all NACOS_USER=nacos JAVA=/usr/local/openjdk-8/bin/java JVM_XMS=1g JVM_XMX=1g JVM_XMN=512m JVM_MS=128m JVM_MMS=320m NACOS_DEBUG=n TOMCAT_ACCESSLOG_ENABLED=false TZ=Asia/Shanghai (You can suppress it with --accept-key) |
2 | CIS-DI-0001 | WARN | Last user should not be root |
3 | CIS-DI-0005 | INFO | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
4 | CIS-DI-0006 | INFO | not found HEALTHCHECK statement |
5 | CIS-DI-0008 | INFO | setuid file: urwxr-xr-x usr/bin/umount |