Skip to main content

Specifying CVEs for trials

kacti can use a CVE identifier instead of an explicit image reference for a trial:

kacti trials --deploy --cve CVE-2021-44228 -n kacti log4shell
-> Success, Deployment creation was blocked

Supported CVEs and images

When you specify a CVE kacti uses a signed image to perform the trial. The following table shows the currently supported CVEs and images for kacti:

CVEImageSourceComments
CVE-2021-44228quay.io/kacti/log4shellhttps://github.com/shaneboulden/log4shell-vulnerable-appLog4Shell image