Property
Languageyaml
Severitymedium
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelHigh
Likelihood LevelLow

Description#

The service configuration explicitly disables SELinux separation by setting ’label:disable’ in ‘security_opt’. This causes the container to run without SELinux protections, leaving it unconfined.

Impact#

Disabling SELinux separation removes important security boundaries, allowing a compromised container to potentially access or modify sensitive files or processes on the host system. This greatly increases the risk of privilege escalation and data breaches.