OpenSCAP and vulnerability scan report:

  • Prisma Cloud Compute release: 21.04 Update 1 (21.04.421)

  • Base image: registry.access.redhat.com/ubi8/ubi-minimal:8.4-200

  • Benchmark URL: scap-security-guide-0.1.54/ssg-rhel8-ds.xml

  • Benchmark ID: xccdf_org.ssgproject.content_benchmark_RHEL-8

  • Profile ID: xccdf_org.ssgproject.content_profile_stig

  • Compared to IronBank’s UBI8-minimal, Version 8.4 Conditionally Approved, Build Date: 2021-06-07T11:31:41.852Z

twistlock/private:console_21_04_421

Findings for Prisma Cloud Compute Console.

OpenSCAP report

Rule_ID Compute finding IronBank finding Justification

xccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy

Pass

Fail

/etc/pki/tls/openssl.cnf configured according to check

xccdf_org.ssgproject.content_rule_banner_etc_issue

Fail

Pass

Application is a non-interactive container. There is no interactive console session with the container.

Vulnerabilities full report

CVE Package Version Fix Status Justification

CVE-2021-27219

glib2

2.56.4-9.el8

fixed in 2.56.4-10.el8_4

To be patched in v21_04 Update 2

twistlock/private:defender_21_04_421

Findings for Prisma Cloud Compute Defender.

OpenSCAP report

Rule_ID Compute finding IronBank finding Justification

xccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy

Pass

Fail

/etc/pki/tls/openssl.cnf configured according to check

xccdf_org.ssgproject.content_rule_banner_etc_issue

Fail

Pass

Application is a non-interactive container. There is no interactive console session with the container.

Vulnerabilities full report

CVE Package Version Fix Status Justification

CVE-2021-27219

glib2

2.56.4-9.el8

fixed in 2.56.4-10.el8_4

To be patched in v21_04 Update 2