- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
A Guide to Managing Docker CVEs
Docker, a platform for building and running containers, offers plenty of benefits, like the ability to run applications with less resource overhead than conventional virtualization and to move apps easily between systems.
Docker, a platform for building and running containers, offers plenty of benefits, like the ability to run applications with less resource overhead than conventional virtualization and to move apps easily between systems.
But like all software tools and frameworks, Docker is also subject to security vulnerabilities. When you use Docker tools to build and run your applications, you face an array of potential security risks, ranging from container escape vulnerabilities, to privilege escalation issues, to Docker image security flaws and beyond.
That’s why taking steps to identify and mitigate Docker security vulnerabilities should be a core element of any strategy for deploying applications using Docker. To provide guidance, this article explains which types of vulnerabilities impact Docker, how to track them and how to remediate Docker security risks.
In this article:
- What is a Docker CVE?
- Types of Docker vulnerabilities
- Docker security examples: Top 4 Docker CVEs
- Best practices to manage Docker risk and vulnerabilities
- Aqua CNAPP: Leading platform for container security
What is a Docker CVE?
Let’s begin by discussing how Docker security vulnerabilities are reported and tracked.
Typically, this happens using the Common Vulnerabilities and Exposure (CVE) system, which tracks known security vulnerabilities. By scanning software they are running and checking the results against lists of CVEs (like those in the Aqua Vulnerability Database), businesses can determine whether any of the software they use is subject to a known vulnerability.
It’s important to note that CVEs record only vulnerabilities that have been publicly documented; it’s possible for risks to exist that have not yet been reported through the CVE system, although scanning for CVEs is a first step toward identifying risks in your software.
Docker CVEs are CVEs associated with any aspect of the Docker software ecosystem – such as the Docker runtime (which executes Docker containers), Docker’s tools for building container images and Docker’s desktop software.
Types of Docker vulnerabilities
Docker vulnerabilities come in many forms. Common examples of risks associated with Docker vulnerabilities include:
- Container escape: This occurs when configuration mistakes or software bugs allow containers to “escape” their container environments and access the host system.
- Malware execution: Vulnerabilities could enable to execute arbitrary code, which means they can plant and run malware on an affected system.
- Container registry security flaws: Container registries can become vulnerable due to misconfigurations, such as missing access controls that allow anyone to download or modify sensitive container images.
- Image vulnerabilities: Vulnerabilities can appear in container images if the images are based on code that contains unpatched vulnerabilities, or if a container image uses vulnerable packages or libraries.
- Runtime vulnerabilities: Bugs in container runtimes like runC, which are the software responsible for executing containers, can allow attackers to take control of containers or, in extreme cases, the host system.
As we mentioned above, risks like these are inherent to application deployment strategies that leverage Docker. They wouldn’t impact traditional applications because those apps don’t typically use resources like images and dedicated runtimes. But when you use containers, your attack surface broadens due to the additional tools necessary to run containerized apps.
Docker security examples: Top 4 Docker CVEs
To illustrate common examples of Docker security vulnerabilities in the real world, here’s a look at what we consider the four most significant Docker CVEs issued to date.
#1. CVE-2019-5736
CVE-2019-5736 is a vulnerability that affects runC, a popular container runtime. It allows attackers to gain root access on vulnerable systems – which effectively means they can take over not just containers, but the entire server that hosts them.
#2. CVE-2018-15664
CVE-2018-15664 also enables attackers to gain root-level privileges on the systems that host containers. In this case, they do so using directory traversal. The direct impact of this vulnerability is limited to allowing root-level read and write access to host file systems; however, by modifying system directories, attackers could potentially plant malware or escalate privileges.
#3. CVE-2022-0185
CVE-2022-0185 is a vulnerability that impacts the Linux kernel, not Docker specifically. Nonetheless, by exploiting the vulnerability, threat actors can launch container escape attacks.
#4. CVE-2019-14271
The vulnerability reported as CVE-2019-14271 allows arbitrary code injection through containers. This effectively means that attackers can load software of their choosing, including malware, onto affected systems.
Best practices to manage Docker risk and vulnerabilities
Typically, vulnerabilities arise due to flaws in the source code for Docker tools or images. This means there’s not much that most organizations that use Docker can do to prevent vulnerabilities, because they don’t typically control the source code.
But what Docker users can do is take steps to identify and protect themselves against vulnerabilities via practices like the following.
Regularly scan Docker images
A key best practice is to scan Docker images regularly using Docker scanning tools. For example, using Trivy, a popular open source scanning tool, teams can generate lists of vulnerabilities inside container images:
Since each new or updated image could contain new vulnerabilities – and because new vulnerabilities are regularly disclosed that could exist in images that were scanned previously – scanning should occur regularly, not just prior to image pulls or application deployment.
Scan software supply chains
Docker tools that a business uses to deploy containers are examples of components in its software supply chain, since Docker is third-party software. This means that the principles of software supply chain security apply to an organization that uses Docker.
Teams should know which Docker tools they’re using, as well as the specific version of each tool. With this information, they can determine whether any Docker components, such as the runtime, are subject to CVEs.
Keep Docker and dependencies updated
Installing updates for Docker and related software (like Kubernetes) whenever they become available is important because updates may patch CVEs. Typically, software vendors or developers release patches to remediate vulnerabilities soon after disclosure of a new CVE, but until users update their software, the vulnerability remains exploitable.
Harden systems
System hardening doesn’t prevent vulnerabilities, but it can make them harder to exploit in some cases. Examples of hardening steps include:
- Configuring file systems to operate in read-only mode.
- Implementing network segmentation to isolate resources from each other.
- Applying the principle of least privilege when configuring access permissions for users and containers.
Aqua CNAPP: Leading platform for container security
As the pioneer and recognized leader in container security, Aqua provides complete end-to-end protection for your container workloads, regardless of where they are deployed. We help you shift left to comprehensively scan your container images, empowering your developers to fix risks early-on, when it costs less. With key acceptance gates set up in the CI/CD pipeline, you can reduce the attack surface before deployment by allowing only authorized images to run. In addition, you can ensure real-time protection of your container workloads in production, prevent drift, detect malware and stop known and sophisticated zero-day attacks as they happen.
- Top OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- What Is Containerization?
- What Is a Virtual Machine (VM)?
- Containerization vs. Virtualization: Key Differences and Use Cases
- Containerized Applications: Components, Use Cases, and Best Practices
- What Are Microservices?
- Registry Scanning: Top 5 Risks and 3 Steps to a Secure Registry
- Understand Docker Monitoring – And Its Relationship to Container Security
- Securing Containers with Docker Scanning
- Docker CIS Benchmark: Best Practices in Brief
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker vs. Virtual Machines: Key Differences
- What Is Docker Architecture?
- What Is Docker Networking? A Practical Guide
- What Is a Docker Registry?
- Docker Orchestration: Swarm vs Kubernetes
- OpenShift vs Docker: Understanding the Difference
- Containers in Cloud Computing: Enabling Portability, Agility and Automation
- Container DevOps: Building Containers into the DevOps Process
- Docker in Production: Getting it Right
- Understanding Container Monitoring: Best Practices and Tools
- Container Advantages: 7 Reasons to Adopt a Containerized Architecture
- Using Docker Hub Responsibly: 4 Security Best Practices
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!