
A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing
A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing.
Vesta is a static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit. It inspects Kubernetes and Docker configures,
cluster pods, and containers with safe practices.
Vesta is a flexible toolkit which can run on physical machines in different types of systems (Windows, Linux, MacOS).
Scan
Docker
| Supported | Check Item | Description | Severity | Reference |
|---|---|---|---|---|
| ✔ | PrivilegeAllowed | Privileged module is allowed. | critical | Ref |
| ✔ | Capabilities | Dangerous capabilities are opening. | critical | Ref |
| ✔ | Volume Mount | Mount dangerous location. | critical | Ref |
| ✔ | Docker Unauthorized | 2375 port is opening and unauthorized. | critical | Ref |
| ✔ | Kernel version | Kernel version is under the escape version. | critical | Ref |
| ✔ | Network Module | Net Module is host and containerd version less than 1.41. | critical/medium | |
| ✔ | Pid Module | Pid Module is host. | high | |
| ✔ | Docker Server version | Server version is included the vulnerable version. | critical/high/ medium/low | |
| ✔ | Docker env password check | Check weak password in database. | high/medium | |
| ✔ | Docker History | Docker layers and environment have some dangerous commands. | high/medium | |
| ✔ | Docker Backdoor | Docker env command has malicious commands. | critical/high | |
| ✔ | Docker Swarm | Docker swarm has dangerous config or secrets or containers are unsafe. | medium/low | |
| ✔ | Docker supply chain | Docker supply chain has vulnerable configurations | critical/high/ medium | Ref |
Kubernetes