5.31 Do not mount the Docker socket inside any containers

Information

The docker socket (docker.sock) should not be mounted inside a container.

Rationale:

If the docker socket is mounted inside a container it would allow processes running within the container to execute docker commands which effectively allows for full control of the host.

Solution

Ensure that no containers mount docker.sock as a volume.

Impact:

None

Default Value:

By default, docker.sock is not mounted inside containers.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 7d222519087bb91cfb91a6d7b1447405abd11730541027f1ac6a2c50a86526f9