All Products
Search
Document Center

Security Center:DescribeCanFixVulList

Last Updated:Sep 17, 2026

Queries the list of fixable vulnerabilities.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeCanFixVulList

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Type

string

Yes

The vulnerability type. Valid values:

  • cve: system vulnerability

  • sca: application vulnerability

cve

Uuids

string

No

The UUIDs of images. Separate multiple UUIDs with commas (,).

d15df12472809c1c3b158606c0f1****

Name

string

No

The name of the vulnerability.

scan:AVD-2022-953356

AliasName

string

No

The alias in the vulnerability advisory.

RHSA-2017:0184-Important: mysql security update

StatusList

string

No

The fix status of the vulnerability. Valid values:

  • 1: Unfixed.

  • 4: Being fixed.

  • 7: Fixed.

1

Necessity

string

No

The priority levels of vulnerabilities to query. Separate multiple levels with commas (,). Valid values:

  • asap: high

  • later: medium

  • nntf: low

asap,later,nntf

Dealed

string

No

Specifies whether the vulnerability is handled. Valid values:

y: Handled. n: Not handled.

n

CurrentPage

integer

No

The page number of the current page in a paging query. The value starts from 1. Default value: 1.

1

PageSize

integer

No

The maximum number of entries per page in a paging query. Default value: 20.

20

RepoRegionId

string

No

The region ID of the image repository. Valid values:

  • cn-beijing: China (Beijing)

  • cn-zhangjiakou: China (Zhangjiakou)

  • cn-hangzhou: China (Hangzhou)

  • cn-shanghai: China (Shanghai)

  • cn-shenzhen: China (Shenzhen)

  • cn-hongkong: Hong Kong (China)

  • ap-southeast-1: Singapore

  • ap-southeast-5: Indonesia (Jakarta)

  • us-east-1: US (Virginia)

  • us-west-1: US (Silicon Valley)

  • eu-central-1: Germany (Frankfurt)

  • eu-west-1: UK (London)

cn-hangzhou

RepoInstanceId

string

No

The ID of the container image instance.

Note

Call the ListRepository operation of Container Registry to obtain the container image instance ID from the InstanceId response parameter.

cri-rv4nvbv8iju4****

RepoId

string

No

The ID of the image repository.

Note

Call the ListRepository operation of Container Registry to obtain the image repository ID from the RepoId response parameter.

crr-avo7qp02simz2njo

RepoName

string

No

The name of the image repository.

Note

Fuzzy match is supported.

digital-account

RepoNamespace

string

No

The namespace of the image repository.

Note

Fuzzy match is supported.

ns-digital-dev

RegionId

string

No

The region ID of the image repository. Valid values:

  • cn-beijing: China (Beijing)

  • cn-zhangjiakou: China (Zhangjiakou)

  • cn-hangzhou: China (Hangzhou)

  • cn-shanghai: China (Shanghai)

  • cn-shenzhen: China (Shenzhen)

  • cn-hongkong: Hong Kong (China)

  • ap-southeast-1: Singapore

  • ap-southeast-5: Indonesia (Jakarta)

  • us-east-1: US (Virginia)

  • us-west-1: US (Silicon Valley)

  • eu-central-1: Germany (Frankfurt)

  • eu-west-1: UK (London)

cn-hangzhou

InstanceId

string

No

The ID of the container image instance.

Note

Call the ListRepository operation of Container Registry to obtain the container image instance ID from the InstanceId response parameter.

cri-rv4nvbv8iju4****

Tag

string

No

The tag of the container image.

0.1.0

Digest

string

No

The unique identifier of the container image.

8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d50****

ClusterId

string

No

The ID of the container cluster.

Note

You can call the DescribeGroupedContainerInstances operation to obtain this parameter.

c80f79959fd724a888e1187779b13****

ScanRange

array

No

The scan scope. Valid values:

  • image: Image.

  • container: Container.

string

No

The collection of scan scopes. Valid values:

  • image: Image.

  • container: Container.

image,container

ClusterName

string

No

The name of the container cluster.

sas-test-cnnf

ContainerId

string

No

The container ID.

48a6d9a92435a13ad573372c3f3c63b7e04d106458141df9f92155709d5a****

Pod

string

No

The name of the pod.

22222-7xsqq

Namespace

string

No

The cluster namespace.

Note

You can call the GetOpaClusterNamespaceList operation to query this value.

default

Image

string

No

The name of the container image.

registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-****

ResourceDirectoryAccountId

integer

No

The ID of the Alibaba Cloud account of a member account in the resource folder.

Note

You can call the DescribeMonitorAccounts operation to obtain this parameter.

127608589417****

Response elements

Element

Type

Description

Example

object

PlainResult<List>

VulRecords

array<object>

The vulnerability information returned by the query.

array<object>

The vulnerability information returned by the query.

CanUpdate

boolean

Indicates whether the software package that causes the vulnerability can be upgraded by using Security Center. Valid values:

  • true: The upgrade is supported.

  • false: The upgrade is not supported.

true

Type

string

The vulnerability type. Valid values:

  • cve: system vulnerability

  • sca: application vulnerability

cve

Status

integer

The fix status of the vulnerability. Valid values:

  • 1: Unfixed.

  • 4: Being fixed.

  • 7: Fixed.

1

ModifyTs

integer

The timestamp when the vulnerability status was modified. Unit: milliseconds.

1620404763000

ImageDigest

string

The unique identifier of the container image.

8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d50****

PrimaryId

integer

The ID of the vulnerability.

782661

Tag

string

The tag of the container image.

latest

RepoNamespace

string

The namespace of the container image repository.

3rdparty

RepoName

string

The name of the container image repository.

varnish

Related

string

The list of CVEs associated with the vulnerability. Multiple values are separated by commas (,).

CVE-2017-7518,CVE-2017-12188

FirstTs

integer

The timestamp when the vulnerability was first detected. Unit: milliseconds.

1620752053000

LastTs

integer

The timestamp when the vulnerability was last detected. Unit: milliseconds.

1620404763000

Necessity

string

The priority level of the vulnerability fix. Valid values:

  • asap: high

  • later: medium

  • nntf: low

Note

Fix vulnerabilities with the high priority level as soon as possible.

asap,later,nntf

Uuid

string

The UUID of the container image.

0004a32a0305a7f6ab5ff9600d47****

AliasName

string

The alias of the vulnerability.

CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read

Name

string

The name of the vulnerability.

debian:10:CVE-2019-9893

Layers

array

The list of container image layers.

string

The list of container image layers.

["8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d50****"]

ExtendContentJson

object

The extended content of the vulnerability information.

OsRelease

string

The release version of the operating system corresponding to the container image.

10.9

Os

string

The name of the operating system.

debian

RpmEntityList

array<object>

The list of RPM packages.

object

The list of RPM packages.

MatchList

array

The rule hits.

string

The rule hits.

["libstdc++ version less than 8.5.0-4.el8_5"]

Layer

string

The SHA256 value of the container image layer digest.

b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1****

FullVersion

string

The full version number of the software package.

3.10.0-693.2.2.el7

Version

string

The version number of the software package.

3.10.0

MatchDetail

string

The details of the vulnerability match.

python-perf version less than 0:3.10.0-693.21.1.el7

Path

string

The path of the software that contains the vulnerability.

/usr/lib64/python2.7/site-packages

Name

string

The name of the software package.

python-perf

UpdateCmd

string

The command to fix the vulnerability.

apt-get update && apt-get install libseccomp2 --only-upgrade

CanFix

string

Indicates whether the vulnerability can be fixed in the console. Valid values:

  • yes: The vulnerability can be fixed.

  • no: The vulnerability cannot be fixed.

yes

ClusterId

string

The cluster ID.

c08d5fc1a329a4b88950a253d082f1****

ClusterName

string

The cluster name.

docker-law

Pod

string

The name of the pod.

22222-7xsqq

Namespace

string

The namespace.

test-002

Image

string

The image name.

registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****

ContainerId

string

The container ID.

04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****

InternetIp

string

The public IP address of the asset.

1.2.XX.XX

IntranetIp

string

The private IP address of the asset.

172.19.XX.XX

InstanceName

string

The instance name.

The name must be 3 to 64 characters in length and can contain letters, digits, hyphens (-), and underscores (_).

testInstance

TargetId

string

The ID of the scan target.

300269

TargetName

string

The name of the scan target.

source-test-obj-XM0Ma

MaliciousSource

string

The source of the malicious file. Valid values:

  • agentless: Agentless detection.

  • image: Image.

  • container: Container.

agentless

TargetType

string

The object type of the scan target. Valid values:

  • IMAGE: Container image.

  • ECS_IMAGE: Host image.

  • ECS_SNAPSHOT: Snapshot.

ECS_IMAGE

ScanTime

integer

The timestamp of the scan. Unit: milliseconds.

1649814050000

RequestId

string

The request ID.

1408FDB3-46F4-513C-9918-FE7D356DF048

Examples

Success response

JSON format

{
  "VulRecords": [
    {
      "CanUpdate": true,
      "Type": "cve",
      "Status": 1,
      "ModifyTs": 1620404763000,
      "ImageDigest": "8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d50****",
      "PrimaryId": 782661,
      "Tag": "latest",
      "RepoNamespace": "3rdparty",
      "RepoName": "varnish",
      "Related": "CVE-2017-7518,CVE-2017-12188",
      "FirstTs": 1620752053000,
      "LastTs": 1620404763000,
      "Necessity": "asap,later,nntf",
      "Uuid": "0004a32a0305a7f6ab5ff9600d47****",
      "AliasName": "CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read",
      "Name": "debian:10:CVE-2019-9893",
      "Layers": [
        "[\"8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d50****\"]"
      ],
      "ExtendContentJson": {
        "OsRelease": "10.9",
        "Os": "debian",
        "RpmEntityList": [
          {
            "MatchList": [
              "[\"libstdc++ version less than 8.5.0-4.el8_5\"]"
            ],
            "Layer": "b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1****",
            "FullVersion": "3.10.0-693.2.2.el7",
            "Version": "3.10.0",
            "MatchDetail": "python-perf version less than 0:3.10.0-693.21.1.el7",
            "Path": "/usr/lib64/python2.7/site-packages",
            "Name": "python-perf",
            "UpdateCmd": "apt-get update && apt-get install libseccomp2  --only-upgrade"
          }
        ]
      },
      "CanFix": "yes",
      "ClusterId": "c08d5fc1a329a4b88950a253d082f1****\n",
      "ClusterName": "docker-law\n",
      "Pod": "22222-7xsqq\n",
      "Namespace": "test-002\n",
      "Image": "registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****\n",
      "ContainerId": "04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****\n",
      "InternetIp": "1.2.XX.XX",
      "IntranetIp": "172.19.XX.XX",
      "InstanceName": "testInstance",
      "TargetId": "300269",
      "TargetName": "source-test-obj-XM0Ma",
      "MaliciousSource": "agentless",
      "TargetType": "ECS_IMAGE",
      "ScanTime": 1649814050000
    }
  ],
  "RequestId": "1408FDB3-46F4-513C-9918-FE7D356DF048"
}

Error codes

HTTP status code

Error code

Error message

Description

400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.