You Should be Using Rootless Containers
- The other day a serious vulnerability was disclosed in one of the newer Linux distributions (the one led by the racist, so it isn't getting a mention here).
- The issue was interesting because it was caused by a non-standard Docker configuration that their installer applied by default, without alerting users that this configuration was creating a security risk.
- The end result was that any process running on these systems had the ability to elevate itself to root, without password, sudo or any prompts to the user.
Unverified
- The other day a serious vulnerability was disclosed in one of the newer Linux distributions (the one led by the racist, so it isn't getting a mention here).
- The issue was interesting because it was caused by a non-standard Docker configuration that their installer applied by default, without alerting users that this configuration was creating a security risk.
- The end result was that any process running on these systems had the ability to elevate itself to root, without password, sudo or any prompts to the user.
Sources: Miguelgrinberg