The Docker daemon API is root on the host by design: anyone who can talk to it can start a privileged container that mounts the host. It listens on a local socket by default, but operators frequently expose it on TCP, on 2375 in plaintext or 2376 with TLS, for remote management and CI. Any reachable daemon API is game over for the host.
Subtopics#
- Unauthenticated daemon access: the plaintext API on 2375.
- Weak TLS on 2376: the TLS port without enforced client certificates.
- API enumeration: mapping the host through the API.
- Host takeover via privileged run: turning API access into host root.