🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Missing Vulnerability Scanning for Container Images

Container images are not configured to be scanned for known vulnerabilities before deployment. Without image vulnerability scanning, insecure base images, outdated operating system packages, vulnerable application dependencies, or accidentally introduced pre-release/debug components may be promoted into production without detection.

This increases the risk that exploitable vulnerabilities are deployed into cloud workloads, where attackers may use them to gain unauthorised access, escalate privileges, access sensitive data, or compromise the availability and integrity of the application environment. Container images should be treated as release artefacts and validated through automated security scanning before they are deployed to production.

Remediation

Enable vulnerability scanning for container images. Where possible, enforce scanning as part of the CI/CD pipeline and block deployment of images that contain high or critical vulnerabilities. Ensure scan results are reviewed regularly, vulnerable images are rebuilt with patched base images and dependencies, and production deployments only use images that have passed security validation.

Metadata

  • Severity: high
  • Slug: missing-vulnerability-scanning-for-container-images

CWEs

  • 693: Protection Mechanism Failure
  • 1269: Product Released in Non-Release Configuration

OWASP

  • A05:2021: Security Misconfiguration

Available Labs

Select a language to explore available labs for this vulnerability.

No matching labs found

Try adjusting your language filter.

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.