8.8 (L1) VMware Tools must deactivate ContainerInfo unless required

Information

Deactivating the ContainerInfo plugin within VMware Tools is advised unless its functionality is required. This plugin collects data on running containers within a Linux guest operating system. The parameter governing this behavior is containerinfo poll-interval with a recommended setting of 0.

Restricting unnecessary data collection is a prudent practice to minimize potential security risks, and to comply with least privilege principles.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Impact:

Disabling ContainerInfo could affect certain products and services within the VMware ecosystem that rely on this functionality, necessitating other configurations or methods to obtain the required container information.

See Also

https://workbench.cisecurity.org/benchmarks/15784

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.1

Plugin: VMware

Control ID: cb4701e6354604113152a7d4515c3d9bff4b1ec093c6e36f81c9c96c3ac0a3f2