https://bugzilla.redhat.com/show_bug.cgi?id=1119282

Stef Walter <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]



--- Comment #27 from Stef Walter <[email protected]> ---
The difference between privilege escalation via sudo and that via docker is
that the former is audited, logged, and uses a well known privilege escalation
path.

Privilege escalation via the docker group (which is correctly not present by
default) is not audited, cannot be logged, is wide open, does not respect
SELinux contexts.

Even the upstream Docker project warns against this.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
_______________________________________________
golang mailing list
[email protected]
https://lists.fedoraproject.org/mailman/listinfo/golang

Reply via email to