Overviewconsole
ghcr.io/pluralsh/console:sha-df25317@sha256:c1bc0072e4491bd83d6d35672790b9113fd145b88cd577c71f13d69d7415f50c
Severity breakdown
Critical
0
High
0
Medium
0
Low
1
Unknown
1
Fixable
1/2
Scanned Sep 23, 2026, 7:10 PM UTC
Actual infrastructure risk
Package finding only; applicability requires a demonstrated execution path. Console is Internet-accessible through NGINX/TLS, has NodePorts, permits all-source ingress to 4000 and unrestricted egress. A proven compromise could use its mounted console service-account token (cluster-admin); read-only root filesystem, no privilege escalation, dropped capabilities and RuntimeDefault seccomp mitigate post-compromise, but non-root is not forced.