# Missing Capability Restrictions - ID: kubernetes-missing-drop-capabilities - Severity: MEDIUM - CWE: CWE-250 (CWE-250) - Languages: YAML - Frameworks: kubernetes ## Description Detects containers that do not drop unnecessary Linux capabilities. ## Detection Message Container doesn't drop unnecessary Linux capabilities. ## Remediation Drop all capabilities in securityContext. ```yaml securityContext: capabilities: drop: [ALL] ``` Learn more: https://shoulder.dev/learn/kubernetes/cwe-250/missing-drop-capabilities ## Documentation [object Object] ## Related Rules - **Container runs as root** [HIGH]: - **Docker User and File Permissions** [HIGH]: - **Privilege Escalation Allowed** [HIGH]: - **Dangerous Linux Capabilities Added** [CRITICAL]: - **Host Namespace Access Enabled** [CRITICAL]: