Ensure the default seccomp profile is not Disabled (Automated)
Seccomp filtering provides a means for a process to specify a filter for incoming system calls. The default Docker seccomp...
Seccomp filtering provides a means for a process to specify a filter for incoming system calls. The default Docker seccomp...
You should verify that the Containerd socket file is owned by root and group owned by root.
Audit /usr/bin/containerd-shim-runc-v2 if applicable.
SELinux is an effective and easy-to-use Linux application security system. It is available by default on some distributions such as...
AppArmor is an effective and easy-to-use Linux application security system. It is available on some Linux distributions by default, for...
You should verify that the Containerd socket file has permissions of 660 or are configured more restrictively.
The SSH daemon should not be running within the container. You should SSH into the Docker host, and use docker...
We have detected an Apache Spark configuration file on the system which doesn't support authentication. This could allow unwanted users...
If TLS is not enabled and configured correctly, this increases the risk of data being compromised in transit.