# Protection Mechanism Failure (CWE-693) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. **Stack:** Docker - Prevalence: Élevée Fréquemment exploitée - Impact: Élevé 1 règles de sévérité élevée - Prevention: Documentée 8 exemples de correctifs **OWASP:** Security Misconfiguration (A05:2021-Security Misconfiguration) - #5 ## Description This weakness covers three distinct situations: Missing a protection mechanism, using a faulty protection mechanism, or incorrectly applying a protection mechanism. A missing protection mechanism occurs when the application does not defend against a specific attack. A faulty protection mechanism occurs when the application does defend against a specific attack, but the protection mechanism is not implemented correctly. ## Prevention Stratégies de prévention pour Protection Mechanism Failure basées sur 1 règles de détection Shoulder. ### Docker Add a HEALTHCHECK instruction to enable container health monitoring ## Warning Signs - [LOW] Dockerfile has no HEALTHCHECK instruction for container health monitoring - [LOW] Dockerfiles missing HEALTHCHECK instructions for container monitoring ## Consequences - Contourner le mécanisme de protection - Exécuter du code non autorisé - Obtenir des privilèges ## Mitigations - Mettez en place plusieurs couches de sécurité (défense en profondeur) - Utilisez des mécanismes de sécurité standards de l'industrie et éprouvés plutôt que des implémentations sur mesure - Assurez-vous que les mécanismes de protection ne peuvent être contournés ni désactivés ## Detection - Total rules: 8 - Languages: dockerfile, go, javascript, typescript ## Rules by Language ### Dockerfile (1 rules) - **Missing Healthcheck Configuration** [LOW]: Detects Dockerfiles missing HEALTHCHECK instructions for container monitoring. - Remediation: Add a HEALTHCHECK instruction to monitor container health. ```dockerfile HEALTHCHECK --interval=30s --timeout=10s --retries=3 \ CMD curl -f http://localhost:8080/health || exit 1 ``` Learn more: https://shoulder.dev/learn/docker/cwe-693/missing-healthcheck