SV-260906r1015768_rule
V-260906
SRG-APP-000033-CTR-000095
CNTR-MK-000110
CAT I
10
To remove unauthorized users from the docker group, access the host CLI and run:
gpasswd -d docker [username to remove]
To ensure that docker.socket is group owned, execute the following:
chown root:docker /var/run/docker.sock
Set the file permissions of the Docker socket file to "660" execute the following:
chmod 660 /var/run/docker.sock
Access to use the docker CLI must be limited to root only.
1. Log on to the host CLI and execute the following:
stat -c %U:%G /var/run/docker.sock | grep -v root:docker
If any output is present, this is a finding.
2. Verify that the docker group has only the required users by executing:
getent group docker
If any users listed are not required to have direct access to MCR, this is a finding.
3. Execute the following command to verify the Docker socket file has permissions of 660 or more restrictive:
stat -c %a /var/run/docker.sock
If permissions are not set to "660", this is a finding.
V-260906
False
CNTR-MK-000110
Access to use the docker CLI must be limited to root only.
1. Log on to the host CLI and execute the following:
stat -c %U:%G /var/run/docker.sock | grep -v root:docker
If any output is present, this is a finding.
2. Verify that the docker group has only the required users by executing:
getent group docker
If any users listed are not required to have direct access to MCR, this is a finding.
3. Execute the following command to verify the Docker socket file has permissions of 660 or more restrictive:
stat -c %a /var/run/docker.sock
If permissions are not set to "660", this is a finding.
M
5595