Skip to content

0309-docker-env-priv-Docker Environment File Permissions Not Set to 644 or More Restrictive

Rule ID

  • 0309-docker-env-priv

Category

  • container

Level

  • warn

Compatible Versions

  • Linux

Description

  • The Docker daemon uses the Docker environment file to set the runtime environment for the Docker daemon. On machines using systemd to manage services, the file is /etc/sysconfig/docker. On other systems, the environment file is /etc/default/docker. Verify that the environment file permissions are correctly set to 644 or more restrictive.

Scan Frequency

  • 0 */30 * * *

Rationale

  • The Docker environment file contains sensitive parameters that may alter the behavior of the Docker daemon at runtime. Therefore, it should be writable only by root to maintain file integrity.

Risk Item

  • Container Security

Audit Method

  • Execute the following command to verify that the environment file permissions are set to 644 or more restrictive:
stat -c %a /etc/sysconfig/docker

Remediation

  • Execute the following command:
#> chmod 644 /etc/sysconfig/docker

This sets the file permissions of the environment file to 644.

Impact

  • None

Default Value

  • By default, the file permissions for this file are correctly set to 644.

References

CIS Controls

  • None

Feedback

Is this page helpful?