2 ms·
Mounting the docker socket makes it trivial to escape to the host since you can just launch a privileged container or mount arbitrary files. Plus the daemon gen
by staticassertion 4y ago
Mounting the docker socket makes it trivial to escape to the host since you can just launch a privileged container or mount arbitrary files. Plus the daemon generally runs as root.
At that point you may want to just run it on the host, but basically you'd better trust whatever it is.