5.32 Ensure that the Docker socket is not mounted inside any containers

Information

The Docker socket docker.sock should not be mounted inside a container.

If the Docker socket is mounted inside a container it could allow processes running within the container to execute Docker commands which would effectively allow for full control of the host.

Solution

You should ensure that no containers mount docker.sock as a volume.

Impact:

None

See Also

https://workbench.cisecurity.org/benchmarks/16041

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(2), 800-53|AC-6(5)

Plugin: Unix

Control ID: 916d392c85edcb3c9646301e87b4aca69ba140e5c463bc2202d0966726e42ad9