jre: container running with low UID

Bug #2068013 reported by Johan Binard
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu Docker Images
New
Undecided
Vladimir Petko

Bug Description

Image tag: ubuntu/jre:17-22.04_44
Digest: sha256:7cb8b71a5655da89654ef10704d67b65768de0ca868d3284c1296d03bf6eaa09

The Chiselled Ubuntu for JRE docker image is running with user with uid 101. It raises a security issue when analyzing the image with a security tool because it might cause a conflict with the host user table (see https://kubesec.io/basics/containers-securitycontext-runasuser/ for more details)

To fix this, the uid must be greater than 10000.

Johan Binard (gorkin)
information type: Private Security → Public Security
Changed in ubuntu-docker-images:
assignee: nobody → Vladimir Petko (vpa1977)
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.