# Execution with Unnecessary Privileges (CWE-250) The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. **Stack:** Docker - Prevalence: 高 频繁被利用 - Impact: 关键 3 条严重级别为关键的规则 - Prevention: 已记录 10 个修复示例 **OWASP:** Broken Access Control (A01:2021-Broken Access Control) - #1 ## Description New weaknesses can be exposed because running with extra privileges gives the product access to resources that are not necessary. In addition, if an attacker can trigger the operation with the higher privileges, the attacker might gain root or administrator privileges. ## Prevention ### Docker Add a USER instruction before CMD/ENTRYPOINT to run as non-root Use a non-root user and restrictive file permissions instead of USER root or chmod 777 ## Warning Signs - [HIGH] No USER instruction before CMD/ENTRYPOINT - container runs as root - [HIGH] CMD or ENTRYPOINT without a preceding USER instruction - [HIGH] Dockerfile contains ...: ... - [HIGH] explicit root user and overly permissive chmod 777 permissions ## Consequences - 获取权限 - 执行未授权代码 - 读取应用程序数据 - 修改应用程序数据 ## Mitigations - 以完成所需任务所需的最低权限运行代码 - 确定组件所需的最小访问权限,并只授予这些权限 - 考虑采用即时 (JIT) 权限模型 ## Detection - Total rules: 10 - Critical: 3 - Languages: dockerfile, yaml ## Rules by Language ### Dockerfile (2 rules) - **Container runs as root** [HIGH]: Detects CMD or ENTRYPOINT without a preceding USER instruction. The container will run as root, which is a security risk. - Remediation: Add a USER instruction before CMD/ENTRYPOINT to run as a non-root user. ```dockerfile USER appuser CMD ["node", "server.js"] ``` Learn more: https://shoulder.dev/learn/docker/cwe-250/missing-user - **Docker User and File Permissions** [HIGH]: Detects explicit root user and overly permissive chmod 777 permissions. - Remediation: Use a non-root user and restrictive file permissions. ```dockerfile RUN adduser -D appuser USER appuser ``` Learn more: https://shoulder.dev/learn/docker/cwe-250/user-permissions