5 ms·
The issue, as another poster pointed out, is not that there are vulnerabilities in the Docker daemon, but that access to the socket inherently gives you access
by manacit 10y ago
The issue, as another poster pointed out, is not that there are vulnerabilities in the Docker daemon, but that access to the socket inherently gives you access to run arbitrary containers in privileged mode. This allows you access to the full host: https://docs.docker.com/engine/reference/run/#/runtime-privilege-and-linux-capabilities https://docs.docker.com/engine/reference/run/#/runtime-privi... and everything that a normal root user can do.
At present, there is no great way to mitigate this if you're tracking the official Docker releases (at least, as far as I know).