For the complete documentation index, see llms.txt. This page is also available as Markdown.

31.01.123 Scan Results

OpenSCAP and vulnerability scan report:

  • Prisma Cloud Compute release: 31.01.123 (31.01.123)

  • Base image: registry.access.redhat.com/ubi8/ubi-minimal:8.8

  • Benchmark URL: scap-security-guide-0.1.68/ssg-rhel8-ds.xml

  • Benchmark ID: xccdf_org.ssgproject.content_benchmark_RHEL-8

  • Profile ID: xccdf_org.ssgproject.content_profile_stig

  • Compared to IronBank’s UBI8-minimal, Version 8.8, Build Date: 2023-05-03T15:02:09

twistlock/private:console_31_01_123

Findings for Prisma Cloud Compute Console.

OpenSCAP report

You can find the OpenSCAP report here.

Rule_ID
Compute finding
IronBank finding
Justification

xccdf_org.ssgproject.content_rule_accounts_authorized_local_users

Fail

Pass

Local accounts include: twistlock = non-root account for service, mongod = mongoDB database & saslauth = authentication libraries. Application is a non-interactive container. There is no interactive console session with the container.

xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists

Fail

Pass

Non-interactive / non-root user twistlock does not have a home directory (/home/twistlock).

Vulnerabilities full report

You can find the full vulnerabilities report here.

CVE
Package
Version
Fix Status
Justification

CVE-2022-1996

github.com/emicklei/go-restful

v2.9.5

Fixed in: 2.16.0

To be patched in next update

CVE-2023-39323

Go

1.20.7

Fixed in: 1.21.2, 1.20.9

To be patched in next update

twistlock/private:defender_31_01_123

Findings for Prisma Cloud Compute Defender.

OpenSCAP report

You can find the OpenSCAP report [here].

Rule_ID
Compute finding
IronBank finding
Justification

xccdf_org.ssgproject.content_rule_configure_crypto_policy

Fail

Pass

FIPS 140-2 Level1 validation / enforcement is available.

xccdf_org.ssgproject.content_rule_configure_gnutls_tls_crypto_policy

Fail

Pass

Only GoLang TLS cipher suites are implemented.

Vulnerabilities full report

You can find the full vulnerabilities report here.

CVE
Package
Version
Fix Status
Justification

CVE-2022-1996

github.com/emicklei/go-restful

v2.9.5

Fixed in: 2.16.0

To be patched in next update

CVE-2023-39323

Go

1.20.7

Fixed in: 1.21.2, 1.20.9

To be patched in next update

Last updated

Was this helpful?