T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Mutable Container Image Deployed Persistently with Broad Network Exposure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–31
Vulnerability Type: Unpinned third-party container image and insecure network binding
Risk Level: MediumComplete Code Snippet:
bash docker run -d --restart=always -p 3001:3001 -v uptime-kuma:/app/data --name uptime-kuma louislam/uptime-kuma:1Technical Analysis
The documented command deploys the third-party image
louislam/uptime-kuma:1. This is a mutable major-version tag rather than an immutable image digest. Consequently, separate executions of the same reviewed command can retrieve different image contents. A compromised registry account, upstream release, or distribution path could cause unreviewed code to execute when a user follows the deployment instructions.The command also uses
--restart=always, causing the container to restart after Docker daemon or host restarts. This increases the duration and operational effect of any vulnerable or compromised image.In addition,
-p 3001:3001publishes the container port on all host interfaces by default. Unless access is restricted elsewhere by a firewall or network policy, the Uptime Kuma interface may be reachable from untrusted networks. The command does not document authentication, TLS termination, firewall restrictions, or reverse-proxy access controls.Attack Path
- A user follows the deployment command from
SKILL.md. - Docker resolves the mutable
louislam/uptime-kuma:1tag at execution time. - If the tag has changed or its supply chain has been compromised, Docker retrieves and runs content that was not part of the audited project.
- The container remains operational across Docker daemon or host restarts because of
--restart=always. - Port 3001 is published on all host interfaces.
- A network attacker who can reach the host may probe the exposed monitoring interface and exploit any application vulnerability or insecure initial configuration present in ...[truncated 1136 chars]
- A user follows the deployment command from
- Remediation
View remediation
Remediation Suggestions
- Pin the container to a reviewed, immutable version and digest:
bash docker run -d \ --restart=unless-stopped \ -p 127.0.0.1:3001:3001 \ -v uptime-kuma:/app/data \ --name uptime-kuma \ louislam/uptime-kuma:<exact-version>@sha256:<verified-digest> - Verify the digest against the publisher's authenticated release information and establish a controlled process for reviewing and updating it.
- Bind the port to
127.0.0.1unless direct external access is explicitly required. Place the service behind an authenticated TLS reverse proxy when remote access is needed. - Restrict inbound traffic with host firewall rules, cloud security groups, or equivalent network policies.
- Document secure initial setup, including administrator authentication, strong credentials, TLS, session security, and access restrictions.
- Harden the container with least-privilege controls where supported, including capability removal, resource limits, and appropriate security profiles.
- Scan the pinned image for known vulnerabilities before deployment and define a reviewed update and rollback procedure.
- Reconsider the unconditional restart policy. Use
--restart=unless-stoppedor an explicitly managed service lifecycle to make administrative shutdown effective.
- Pin the container to a reviewed, immutable version and digest:
