Merge pull request #22063 from graingert/patch-1

Fix security documentation, XSS -> CSRF
Upstream-commit: 1d9a6833d319f750a2338ca2b8f6efc318092e04
Component: engine
This commit is contained in:
Vincent Demeester
2016-04-15 14:43:18 +02:00
+1 -1
View File
@@ -106,7 +106,7 @@ arbitrary containers.
For this reason, the REST API endpoint (used by the Docker CLI to
communicate with the Docker daemon) changed in Docker 0.5.2, and now
uses a UNIX socket instead of a TCP socket bound on 127.0.0.1 (the
latter being prone to cross-site-scripting attacks if you happen to run
latter being prone to cross-site request forgery attacks if you happen to run
Docker directly on your local machine, outside of a VM). You can then
use traditional UNIX permission checks to limit access to the control
socket.