Description
Giving the application account ownership through COPY --chown can allow it to modify code, depending on file permissions. A compromised application can cause greater damage if that account can also alter executables or configuration.
--chown is not inherently unsafe. It can support non-root execution and necessary data writes. Review the files’ purpose and effective file, directory and mount permissions together.
Potential impact
- If the runtime account can modify code, an attacker can change application behavior or leave malicious code after a compromise.
- Removing write access from required data directories can break the application.
Remediation
- Separate application code from writable data and grant the runtime account write access only to necessary paths.
- Configure code ownership and modes together. Verify that the non-root account can read and execute the code without modifying it; root ownership alone does not guarantee this.
Examples
The examples compare ownership of copied files. Also check source file modes and the application’s actual write paths.
Before
dockerfile
FROM python:3.12-slim
RUN useradd -ms /bin/bash appuser
COPY --chown=appuser:appuser app /app
WORKDIR /app
USER appuser
CMD ["python", "app.py"]
After
dockerfile
FROM python:3.12-slim
RUN useradd -ms /bin/bash appuser
COPY app /app
WORKDIR /app
USER appuser
CMD ["python", "app.py"]
Explanation:
- Before: appuser owns the copied files. Effective write access depends on file and directory permissions.
- After: Files are copied with default root ownership and the application runs as appuser. Required read/execute access and restrictions on code writes still need verification.