Remediation
Update the ECS Task Definition to Update Privileged Parameterβ
Using the AWS CLIβ
-
Retrieve the existing task definition JSON
aws ecs describe-task-definition \
--task-definition {{family-or-full-arn}} \
--query 'taskDefinition' > task-def.json -
Edit
task-def.jsonFor every container in the
containerDefinitionslist, changeprivilegedto false or remove the key (default is false)."containerDefinitions": [
{
"name": "{{app}}",
"image": "{{image}}",
"privileged": false,
...
}
] -
Register the updated task definition
aws ecs register-task-definition --cli-input-json file://task-def.json -
Update your ECS service to use the new task definition revision