JDWP Misconfiguration in Container Images and K8s
ID: 3ed03b20-3287-51ba-ba51-409f7a0e1ddc
STIX ID: report--3ed03b20-3287-51ba-ba51-409f7a0e1ddc
Feed Name: Aqua Security Blog
This report describes how enabling Java Debug Wire Protocol (JDWP) in container images or pods can expose production environments to remote code execution: Team Nautilus used dynamic scanning and offensive tools (nmap, Metasploit, JDWP-shellifier) to demonstrate gaining root shells in containers and showed that Aqua’s DTA found 193 images across 114 Docker Hub accounts with the misconfiguration; recommended mitigations include disabling JDWP in production, avoiding -agentlib/-Xrunjdwp/-Xdebug in images, restricting network access, and scanning images for JDWP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
