Container Security

Security rules for Docker Compose services

10
Security Rules

Run All Container Security Rules

pathfinder scan --ruleset cpf/docker-compose/security

Rules

Privileged Container Service

critical

Detects services running with privileged mode which disables container isolation

docker-composecontainer-escapeprivilege-escalation
CWE-250
Updated 2024-12-10

Docker Socket Exposed to Container

critical

Service mounts Docker socket providing unrestricted root access to host

docker-composecontainer-escapesecurity
CWE-250
Updated 2024-12-10

Host Network Mode

high

Service uses host network mode bypassing Docker network isolation

docker-composenetworkisolation
CWE-250
Updated 2024-12-10

Seccomp Confinement Disabled

high

Service disables seccomp which restricts system calls, significantly increasing attack surface

docker-composesecurityseccomp
CWE-284
Updated 2024-12-10

Container Filesystem is Writable

low

Service without read-only filesystem allows attackers to modify binaries and persist backdoors

docker-composesecurityimmutability
CWE-732
Updated 2024-12-10

Dangerous Capability Added

high

Service adds dangerous capabilities (SYS_ADMIN, NET_ADMIN, SYS_PTRACE) that can enable container escape

docker-composesecuritycapabilities
CWE-250
Updated 2024-12-10

Using Host PID Mode

high

Service uses host PID namespace allowing it to see and interact with all host processes

docker-composesecurityisolation
CWE-250
Updated 2024-12-10

Using Host IPC Mode

medium

Service uses host IPC namespace allowing it to access shared memory and semaphores of host system

docker-composesecurityisolation
CWE-250
Updated 2024-12-10

Missing no-new-privileges Security Option

medium

Service missing no-new-privileges option allows privilege escalation through setuid/setgid binaries

docker-composesecurityprivilege-escalation
CWE-732
Updated 2024-12-10

SELinux Separation Disabled

medium

Service explicitly disables SELinux which provides mandatory access control limiting container compromise impact

docker-composesecurityselinux
CWE-732
Updated 2024-12-10
Container Security Security Rules for Docker Compose - 10 SAST Rules | Code Pathfinder | Code Pathfinder