{"id":93156,"date":"2020-09-03T19:42:00","date_gmt":"2020-09-03T17:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov"},"modified":"2020-09-03T19:42:00","modified_gmt":"2020-09-03T17:42:00","slug":"uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","title":{"rendered":"Vulnerabilities in Docker container image security scanners","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-2-5-exploiting-cve-scanners-b37766f73005\">Published<\/a><\/noindex> Results of testing tools for identifying unpatched vulnerabilities and detecting security issues in Docker container images. The check revealed that 4 out of 6 known Docker image scanners contained critical vulnerabilities that allow direct attacks on the scanner itself, enabling execution of the attacker's code on the system, in some cases (e.g., with Snyk) gaining root privileges. <\/p>\n<p>To launch an attack, an attacker only needs to initiate a scan of their Dockerfile or manifest.json, which includes specially crafted metadata, or to place Podfile and gradlew files inside the image. Prototypes of exploits <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\">have been prepared<\/a><\/noindex> for systems<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.whitesourcesoftware.com\/whitesource-for-containers\/\">WhiteSource<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/r\/snyk\/snyk-cli\">Snyk<\/a><\/noindex>,<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/r\/fossa\/fossa-cli\">Fossa<\/a><\/noindex> and<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/u\/anchore\">Anchore<\/a><\/noindex>. The best security was demonstrated by the package <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/quay\/clair\">Clair<\/a><\/noindex>, originally written with security in mind. No issues were found in the package <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/aquasecurity\/trivy\">Trivy<\/a><\/noindex>. As a result, it was concluded that Docker container scanners should be run in isolated environments or used only for checking one\u2019s own images, while also exercising caution when connecting such tools to automated continuous integration systems.<\/p>\n<p>In FOSSA, Snyk, and WhiteSource, the vulnerability was linked to calling an external package manager to determine dependencies, allowing for execution of the attacker's code by specifying touch and system commands in the files <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/snyk\/gradle\">gradlew<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/fossa\/cocoa\">Podfile<\/a><\/noindex>.<\/p>\n<p>In Snyk and WhiteSource, additional <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/whitesource\/pip\">issues were found<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/snyk\/docker\">a vulnerability<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/whitesource\/generic\">related<\/a><\/noindex> with the organization of launching system commands when parsing Dockerfile (for example, in Snyk, it was possible to replace the utility \/bin\/ls called by the scanner, and in WhiteSource, code could be injected via arguments in the form of \"echo '';touch \/tmp\/hacked_whitesource_pip;=1.0\"). <\/p>\n<p>In Anchore, the vulnerability <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/anchore\">was caused by<\/a><\/noindex> the use of the utility <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containers\/skopeo\">skopeo<\/a><\/noindex> for working with Docker images. The operation was reduced to adding parameters of the form '\"os\": \"$(touch hacked_anchore)\"' to the manifest.json file, which are substituted during the skopeo invocation without proper escaping (only characters \"&amp;\\<\/p>\n<p>The same author conducted a study on the effectiveness of detecting unpatched vulnerabilities with Docker container security scanners and the level of false positives (<noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-1-false-negatives-and-what-they-mean-for-your-security-77fc4eb1b2cf\">Part 1<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-2-how-good-is-package-detection-f68d7230b830\">Part 2<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-3-test-it-yourself-conclusions-6de868124d3d\">Part 3<\/a><\/noindex>). Below are the test results of 73 images containing known vulnerabilities, as well as an assessment of the effectiveness of detecting standard applications in the images (nginx, tomcat, haproxy, gunicorn, redis, ruby, node).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/miro.medium.com\/max\/840\/1*4CS8SAbix-domsIWNgrk5A.png\"><img decoding=\"async\" alt=\"Vulnerabilities in Docker container image security scanners \" src=\"\/wp-content\/uploads\/2020\/09\/001d442a6b6467583ca1668b68fdc81f.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/miro.medium.com\/max\/840\/1*Xxbob0nabha6N6ZBfBuSLg.png\"><img decoding=\"async\" alt=\"Vulnerabilities in Docker container image security scanners \" src=\"\/wp-content\/uploads\/2020\/09\/eb765e141efe5d22954742eb0cc1470e.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53650\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u0432 \u043e\u0431\u0440\u0430\u0437\u0430\u0445 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 Docker. \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043f\u043e\u043a\u0430\u0437\u0430\u043b\u0430, \u0447\u0442\u043e \u0432 4 \u0438\u0437 6 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0445 \u0441\u043a\u0430\u043d\u0435\u0440\u043e\u0432 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0441\u0430\u043c \u0441\u043a\u0430\u043d\u0435\u0440 \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u043b\u0443\u0447\u0430\u044f\u0445 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 Snyk) \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0414\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":93157,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-93156","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u043a\u0430\u043d\u0435\u0440\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-03T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-03T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in Docker container image security scanners | ProHoster","description":"The results of the testing of tools for detection have been published.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u043a\u0430\u043d\u0435\u0440\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-03T17:42:00+00:00","article:modified_time":"2020-09-03T17:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"93156","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:54:00","updated":"2022-10-01 01:38:05","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=93156"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93156\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/93157"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=93156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=93156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=93156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}