5.31 Ensure that the Docker socket is not mounted inside any containers

Information

The Docker socket docker.sock should not be mounted inside a container.

Rationale:

If the Docker socket is mounted inside a container it could allow processes running within the container to execute Docker commands which would effectively allow for full control of the host.

Solution

You should ensure that no containers mount docker.sock as a volume.

Impact:

None

Default Value:

By default, docker.sock is not mounted inside containers.

See Also

https://workbench.cisecurity.org/files/2433

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CSCv6|9

Plugin: Unix

Control ID: 80107c4c6292cd7fa29d9bc080c491d9fe3de79d6ff956752ac90f71312ce462