[avd-ksv-0109] bitnami/redis helm chart "Storing secrets in configMaps is unsafe" false detection #8329
Closed
ktzsolt
started this conversation in
False Detection
Replies: 2 comments 3 replies
-
|
thanks for the report @ktzsolt - you're right in the sense that this is a false positive. The current check does a regex match and checks to see if there's a value set. In this case the value is set but is evaluated from env vars. @nikpivkin I recall we had a similar issue earlier with another check, didn't we? |
Beta Was this translation helpful? Give feedback.
2 replies
-
|
Duplicate of #8865 |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
avd-ksv-0109
Description
Scanning the helm chart bitnami/redis with
trivy configwill give the following false detections:When in fact the ConfigMap keys contain only shell scripts that are referencing REDIS_PASSWORD environment variable but the REDIS_PASSWORD variable value is not stored in the ConfigMap. The REDIS_PASSWORD env var is created in the container from the release-name-redis Secret like this:
Reproduction Steps
Target
Kubernetes
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions