[medium] semgrep: Service 'mailserver' allows for privilege escalation via setuid or setgid binaries. Add 'no-new-privileges:true' in 'security_opt' to prevent this. #28
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
medium Finding
Scanner: semgrep
Severity: medium
Rule: yaml.docker-compose.security.no-new-privileges.no-new-privileges
Description
Service 'mailserver' allows for privilege escalation via setuid or setgid binaries. Add 'no-new-privileges:true' in 'security_opt' to prevent this.
Location
File:
/tmp/compliance-scanner/repos/Compliance Scanner/deploy/docker-compose.mailserver.yml(line 4)Code
Fingerprint:
e67b8b8b43d137f064fe7a474eacd1f6930535ec07565e5279870d1d2658c58dGenerated by compliance-scanner
Labels: severity:medium, scanner:semgrep, compliance-scanner