1. Home
  2. Security Hardening
  3. CIS Docker 1.13.0 V1.0.0 L2 Docker
  4. Do not docker exec commands with privileged option

Do not docker exec commands with privileged option

Details

Do not docker exec with –privileged option.

Rationale:

Using –privileged option in docker exec gives extended Linux capabilities to the command. This could potentially be insecure and unsafe to do especially when you are running containers with dropped capabilities or with enhanced restrictions.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Do not use –privileged option in docker exec command.

Impact:

None. If you need enhanced capabilities within the container, then run the container with the needed capabilities.

Default Value:

By default, docker exec command runs without –privileged option.

Supportive Information

The following resource is also helpful.

This control applies to the following type of system Unix.

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles