Queries the details of emergency vulnerabilities.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeEmgVulItem |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
The language type for the request and response messages. Default value: zh. Valid values:
|
zh |
| RiskStatus |
string |
No |
The risk status of the vulnerabilities to query. If this parameter is not specified, vulnerabilities of all risk statuses are returned, including those with risks and those without risks. Valid values:
|
y |
| ScanType |
string |
No |
The detection method of the vulnerabilities to query. If this parameter is not specified, vulnerabilities detected by all methods are returned by default, including version detection and network scanning. Valid values:
|
python |
| CheckType |
integer |
No |
The check type. Valid values:
|
0 |
| VulName |
string |
No |
The name of the emergency vulnerability to query. |
Changjietong T + SetupAccount/Upload.aspx file Upload vulnerability (CNVD-2022-60632) |
| CurrentPage |
integer |
No |
The page number of the first page to return. Default value: 1, which indicates that query results are displayed starting from page 1. |
1 |
| PageSize |
integer |
No |
The number of entries per page in a paged query. Default value: 10, which indicates that 10 emergency vulnerability entries are displayed per page. Maximum value: 50. |
10 |
| ResourceDirectoryAccountId |
integer |
No |
The ID of the member accounts in the resource directory (Alibaba Cloud account). Note
Invoke the DescribeMonitorAccounts operation to obtain this parameter. |
127608589417**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| CurrentPage |
integer |
The page number of the returned page. The value starts from 1. Default value: 1, which indicates that the first page is returned. |
1 |
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
BC1868ED-A0E1-4D1C-BF7E-10DC0C34B3C3 |
| PageSize |
integer |
The number of emergency vulnerability entries per page in a paged query. Default value: 10, which indicates that 10 emergency vulnerability entries are displayed per page. Paging is used to display the results. |
10 |
| TotalCount |
integer |
The total number of emergency vulnerabilities returned. |
1 |
| GroupedVulItems |
array<object> |
The information about the emergency vulnerabilities. |
|
|
object |
|||
| Status |
integer |
The detection status of the vulnerability. Valid values:
|
30 |
| Type |
string |
The detection method of the vulnerability. Valid values:
|
scan |
| CheckType |
integer |
The check type. |
1 |
| GmtLastCheck |
integer |
The timestamp of the most recent vulnerability detection. Unit: milliseconds. |
1619286031000 |
| Progress |
integer |
The detection progress of the vulnerability. Value range: 0 to 100. Note
This parameter is displayed only for emergency vulnerabilities that are in the detecting state. |
50 |
| Description |
string |
The description of the vulnerability. |
Chanjet T-Plus is an Internet business management software. There is an unauthorized access vulnerability in one of its interfaces disclosed on the Internet. Attackers can construct malicious requests to upload malicious files to execute arbitrary code and control the server. |
| GmtPublish |
integer |
The timestamp when the vulnerability was published. Unit: milliseconds. |
1618887687000 |
| PendingCount |
integer |
The number of unfixed vulnerabilities. |
0 |
| AliasName |
string |
The name of the vulnerability. |
Changjietong T + SetupAccount/Upload.aspx file Upload vulnerability (CNVD-2022-60632) |
| Name |
string |
The name of the scan rule. |
scan:AVD-2021-179344 |
| RaspDefend |
integer |
Indicates whether Runtime Application Self-Protection (RASP) real-time protection is supported. Valid values:
Note
If this property is not present, RASP real-time protection is not supported. |
1 |
Examples
Success response
JSON format
{
"CurrentPage": 1,
"RequestId": "BC1868ED-A0E1-4D1C-BF7E-10DC0C34B3C3",
"PageSize": 10,
"TotalCount": 1,
"GroupedVulItems": [
{
"Status": 30,
"Type": "scan",
"CheckType": 1,
"GmtLastCheck": 1619286031000,
"Progress": 50,
"Description": "Chanjet T-Plus is an Internet business management software. There is an unauthorized access vulnerability in one of its interfaces disclosed on the Internet. Attackers can construct malicious requests to upload malicious files to execute arbitrary code and control the server.",
"GmtPublish": 1618887687000,
"PendingCount": 0,
"AliasName": "Changjietong T + SetupAccount/Upload.aspx file Upload vulnerability (CNVD-2022-60632)",
"Name": "scan:AVD-2021-179344",
"RaspDefend": 1
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NoPermission | no permission | |
| 400 | UnknownError | UnknownError | |
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | ServerError | ServerError | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 403 | NoPermission | caller has no permission |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.