5.4 Do not use privileged containers

Information

https://docs.docker.com/reference/commandline/cli

Solution

Do not run container with the --privileged flag.For example, do not start a container as below-docker run --interactive --tty --privileged centos /bin/bashImpact-Linux Kernel Capabilities other than defaults would not be available for use within
container.Default Value-False.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(4)

Plugin: Unix

Control ID: 5373604796c11ade1e1e7a08f1b8e9dc94158eef4bbf97914b5aa6a6f7e8bace