5.31 Do not mount the Docker socket inside any containers

Information

The docker socket (docker.sock) should not be mounted inside a container.If the docker socket is mounted inside a container it would allow processes running within
the container to execute docker commands which effectively allows for full control of the
host.

Solution

Ensure that no containers mount docker.sock as a volume.Impact-NoneDefault Value-By default, docker.sock is not mounted inside containers.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 613299629e443a89230c422052bf67b81a6d008d19a860f724856bb10f4e25a7