5.31 Do not mount the Docker socket inside any containers

Information

The docker socket (docker.sock) should not be mounted inside a container.

Rationale:

If the docker socket is mounted inside a container it would allow processes running within the container to execute docker commands which effectively allows for full control of the host.

Solution

Ensure that no containers mount docker.sock as a volume.

Impact:

None

Default Value:

By default, docker.sock is not mounted inside containers.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 392b278b6e8f9ed03e1202bc0d50317eb6ccadd8340c9bdf86572ff66f5ae959