Skip to content

Public service exposure

Docker API open to the internet

Whether the unencrypted Docker API port (2375) accepts a connection from the internet.

Part of the External Security Check. Free during the preview.

What it checks

Whether the unencrypted Docker API port (2375) accepts a connection from the internet.

A pass means: No container management API accepts connections from the internet.

Possible findings

Container API port reachable from the internet

Severity: HighConfidence: Medium confidenceKind: Security issue

What we found

The Docker API port (2375) accepted a connection from the internet.

Why it matters

An unauthenticated Docker API gives full control of the host to anyone who can reach it.

How to fix it

Close port 2375 to the internet immediately. If remote access is needed, use the TLS-protected port with client certificates, behind a firewall.

References