SV-260938r1015771_rule
V-260938
SRG-APP-000342-CTR-000775
CNTR-MK-001180
CAT II
10
Docker CLI command must only be run with a client bundle and must not use --privileged or --user option.
Refer to https://docs.mirantis.com/mke/3.7/ops/access-cluster/client-bundle/configure-client-bundle.html?highlight=client%20bundle.
The host OS must be locked down so that only authorized users with a client bundle can access docker commands.
To ensure that no commands with privilege or user authorizations are present via CLI:
Linux: As a trusted user on the host operating system, use the below command to filter out docker exec commands that used --privileged or --user option.
sudo ausearch -k docker | grep exec | grep privileged | grep user
If there are any in the output, then this is a finding.
V-260938
False
CNTR-MK-001180
The host OS must be locked down so that only authorized users with a client bundle can access docker commands.
To ensure that no commands with privilege or user authorizations are present via CLI:
Linux: As a trusted user on the host operating system, use the below command to filter out docker exec commands that used --privileged or --user option.
sudo ausearch -k docker | grep exec | grep privileged | grep user
If there are any in the output, then this is a finding.
M
5595