3 ms·
So, it can be exploited having access to the machine where docker is running and then using docker cp? can someone make a real use case of this bug?
by esseti 7y ago
So, it can be exploited having access to the machine where docker is running and then using docker cp?
can someone make a real use case of this bug?
- Leynos 7y agoThe suggestion in the linked post is a situation where the Docker daemon is being controlled via its API in a multi-tennant environment where user configuration files are loaded into the container via the cp endpoint. I could concieve of this being a risk if you allow users to create symlinks in the location where the configuration files are situated.
- hclaria 7y agoExcept giving access to a docker daemon equals giving the root access to the machine because it's easy to do something such as : $ docker run -it -v /:/hostfs debian chroot /hostfs # I'm root !
- the8472 7y agoThe issue is an unprivileged container fooling the host, not the host intentionally escalating to root.
- Leynos 7y agoIndeed. The point discussed in the grandparent relates to indirect access to the daemon. E.g., a process (not under direct user control) communicating with the Docker daemon via http API. The point being that the cp endpoint can be compromized without the user having direct control over the API parameters.