The issue isn't that the containers have permissions they weren't assigned. It's that the system configuration allows any (host) user to make a container with any permissions, without sudo.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments