.spec .volumes[] .hostPath .path == "/var/run/docker.sock"

Mounting the docker.socket leaks information about other containers and can allow container breakout

Try it on Katacoda

Built with by controlplane