Queries the details of vulnerabilities detected by image security scans and the list of container images affected by the vulnerabilities.
Operation description
To view the latest container image vulnerability information, call the PublicCreateImageScanTask operation to create an image scan task first. Wait 1 to 5 minutes, and then call this operation to query the container image vulnerability list.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:DescribeImageVulList |
get |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Lang |
string |
No |
The language type of the request and response. Default value: zh. Valid values:
|
zh |
| Type |
string |
Yes |
The type of the vulnerability to query. Set the value to cve, which indicates container image vulnerabilities. |
cve |
| Uuids |
string |
No |
The UUIDs of the asset instances. Separate multiple UUIDs with commas (,). |
0004a32a0305a7f6ab5ff9600d47**** |
| Name |
string |
No |
The name of the vulnerability to query. |
debian:10:CVE-2019-9893 |
| AliasName |
string |
No |
The alias of the vulnerability to query. |
High severity vulnerability that affects org.eclipse.jetty:jetty-server |
| StatusList |
string |
No |
The fix status of the vulnerability. Valid values:
|
1 |
| Necessity |
string |
No |
The priority of vulnerability fixing. Valid values:
|
asap |
| Dealed |
string |
No |
Specifies whether the vulnerability has been handled. Valid values:
|
y |
| CurrentPage |
integer |
No |
The page number of the page to return in the query results. Default value: 1, which indicates that the first page is returned. |
1 |
| PageSize |
integer |
No |
Settings for paged query. The number of vulnerabilities to display on each page during paging. Default value: 10, which indicates that 10 vulnerabilities are displayed on each page. |
10 |
| RepoRegionId |
string |
No |
The region ID of the container image repository. |
cn-hangzhou |
| RepoInstanceId |
string |
No |
The instance ID of the container image repository. |
i-qewqrqcsadf**** |
| RepoId |
string |
No |
The ID of the container image repository. |
qew**** |
| RepoName |
string |
No |
The name of the container image repository. |
libssh2 |
| RepoNamespace |
string |
No |
The namespace of the container image repository. |
libssh2 |
| RegionId |
string |
No |
The region ID of the instance. |
cn-hangzhou |
| InstanceId |
string |
No |
The ID of the asset instance. |
1-qeqewqw**** |
| Tag |
string |
No |
The tag of the container image. |
oval |
| Digest |
string |
No |
The unique identifier of the container image. |
8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012 |
| ClusterId |
string |
No |
The ID of the container cluster. |
cc20a1024011c44b6a8710d6f8b**** |
| ScanRange |
array |
No |
The collection of scan ranges. |
|
|
string |
No |
The scan range. Valid values:
|
container |
|
| ClusterName |
string |
No |
The cluster name. |
docker-law |
| ContainerId |
string |
No |
The container ID. |
c08d5fc1a329a4b88950a253d082f**** |
| Pod |
string |
No |
The pod. |
22222-7xsqq |
| Namespace |
string |
No |
The namespace. |
test-002 |
| Image |
string |
No |
The container image name. |
registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-**** |
| RuleTag |
string |
No |
The vulnerability tag. Valid values:
|
AI |
| GroupByAsset |
boolean |
No |
Specifies whether to group results by image asset before pagination. If set to true, one vulnerability record is returned for each asset, and TotalCount indicates the total number of assets. If set to false or not specified, results are paginated by vulnerability record. Asset grouping is not applied when MaxId is specified. |
|
| ResourceDirectoryAccountId |
integer |
No |
The ID of the Alibaba Cloud account that is added as one of the member accounts in a resource folder. Note
Invoke the DescribeMonitorAccounts operation to obtain this parameter. |
127608589417**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| CurrentPage |
integer |
The page number of the current page when paging is used. |
1 |
| PageSize |
integer |
The number of vulnerabilities displayed per page when paging is used. Default value: 10, which indicates that 10 vulnerabilities are displayed per page. |
10 |
| RequestId |
string |
The ID of the request. Alibaba Cloud generates a unique identifier for each request. You can use the ID to troubleshoot issues. |
D6B20156-49B0-5CF0-B14D-7ECA4B50DAAB |
| TotalCount |
integer |
The total number of vulnerabilities returned by the query. |
1 |
| VulRecords |
array<object> |
The list of vulnerability information. |
|
|
array<object> |
The vulnerability information. |
||
| AgentlessCanFix |
boolean |
Indicates whether the vulnerability supports agentless remediation. true: supported. false: not supported. If this field is not returned, no corresponding remediation capability information is available. |
|
| AliasName |
string |
The alias of the vulnerability. |
CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read |
| CanFix |
string |
Indicates whether the vulnerability can be fixed from the console. Valid values:
|
yes |
| CanUpdate |
boolean |
Indicates whether the software package that causes the vulnerability can be upgraded through Security Center. Valid values:
|
true |
| ClusterId |
string |
The cluster ID. |
c08d5fc1a329a4b88950a253d082f1**** |
| ClusterName |
string |
The cluster name. |
docker-law |
| ContainerId |
string |
The container ID. |
04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163**** |
| ExtendContentJson |
object |
The extended content of the vulnerability information. |
|
| Os |
string |
The name of the operating system. |
debian |
| OsRelease |
string |
The operating system release version corresponding to the container image. |
10.9 |
| RpmEntityList |
array<object> |
The list of software packages that cause the vulnerability. |
|
|
object |
The information about the software package that causes the vulnerability. |
||
| FullVersion |
string |
The full version number of the software package. |
2.3.3-4 |
| Layer |
string |
The SHA256 digest of the container image layer. |
b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1c587 |
| MatchDetail |
string |
The details of the vulnerability match. |
libseccomp2 version less than equals 2.3.3-4 |
| MatchList |
array |
The list of matched rule details. |
["libseccomp2 version less than equals 2.3.3-4"] |
|
string |
The details of matched rules. Details of multiple rules are separated by commas (,). |
["libstdc++ version less than 8.5.0-4.el8_5"] |
|
| Name |
string |
The name of the software package. |
libseccomp2 |
| Path |
string |
The path of the vulnerable software. |
/usr/lib64/libssh2.so.1 |
| UpdateCmd |
string |
The command to fix the vulnerability. |
apt-get update && apt-get install libseccomp2 --only-upgrade |
| Version |
string |
The version number of the software package. |
2.3.3-4 |
| FirstTs |
integer |
The timestamp of the first scan, in milliseconds. |
1620752053000 |
| Image |
string |
The image name. |
registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta**** |
| ImageDigest |
string |
The unique identifier of the container image. |
8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012 |
| InstanceName |
string |
The name of the asset instance. |
testInstance |
| InternetIp |
string |
The public IP address of the server. |
1.2.XX.XX |
| IntranetIp |
string |
The private IP address of the server. |
172.19.XX.XX |
| LastTs |
integer |
The timestamp of the most recent scan, in milliseconds. |
1631779996000 |
| Layers |
array |
The list of container image layers. |
|
|
string |
The list of container image layers. |
["null"] |
|
| MaliciousSource |
string |
The source of the malicious file. Valid values:
|
agentless |
| ModifyTs |
integer |
The timestamp when the vulnerability record was updated, in milliseconds. |
1580808765000 |
| Name |
string |
The name of the vulnerability. |
debian:10:CVE-2019-9893 |
| Namespace |
string |
The namespace. |
test-002 |
| Necessity |
string |
The priority of vulnerability fixing. Valid values:
|
asap |
| Pod |
string |
The pod. |
22222-7xsqq |
| PrimaryId |
integer |
The ID of the vulnerability. |
782661 |
| Related |
string |
The details of the associated vulnerability. |
CVE-2019-9893 |
| RepoName |
string |
The name of the container image repository. |
varnish |
| RepoNamespace |
string |
The namespace of the container image repository. |
default |
| RuleTag |
string |
The vulnerability tag. Valid values:
|
AI |
| ScanTime |
integer |
The timestamp of the scan, in milliseconds. |
1649814050000 |
| Status |
integer |
The fix status of the vulnerability. Valid values:
|
1 |
| Tag |
string |
The tag of the container image vulnerability. |
oval |
| TargetId |
string |
The ID of the scan target. |
m-bp17m0pc0xprzbwo**** |
| TargetName |
string |
The name of the scan target. |
source-test-obj-XM0Ma |
| TargetType |
string |
The object type of the scan target. Valid values:
|
ECS_IMAGE |
| Type |
string |
The type of the vulnerability queried. The value is fixed as cve, which indicates container image vulnerabilities. |
cve |
| Uuid |
string |
The UUID of the server. |
0004a32a0305a7f6ab5ff9600d47**** |
Examples
Success response
JSON format
{
"CurrentPage": 1,
"PageSize": 10,
"RequestId": "D6B20156-49B0-5CF0-B14D-7ECA4B50DAAB",
"TotalCount": 1,
"VulRecords": [
{
"AgentlessCanFix": false,
"AliasName": "CVE-2018-25010:libwebp up to 1.0.0 ApplyFilter out-of-bounds read",
"CanFix": "yes",
"CanUpdate": true,
"ClusterId": "c08d5fc1a329a4b88950a253d082f1****\n",
"ClusterName": "docker-law\n",
"ContainerId": "04d20e98c8e2c93b7b864372084320a15a58c8671e53c972ce3a71d9c163****\n",
"ExtendContentJson": {
"Os": "debian",
"OsRelease": "10.9",
"RpmEntityList": [
{
"FullVersion": "2.3.3-4",
"Layer": "b1f5b9420803ad0657cf21566e3e20acc08581e7f22991249ef3aa80b8b1c587",
"MatchDetail": "libseccomp2 version less than equals 2.3.3-4",
"MatchList": [
"[\"libstdc++ version less than 8.5.0-4.el8_5\"]"
],
"Name": "libseccomp2",
"Path": "/usr/lib64/libssh2.so.1",
"UpdateCmd": "apt-get update && apt-get install libseccomp2 --only-upgrade",
"Version": "2.3.3-4"
}
]
},
"FirstTs": 1620752053000,
"Image": "registry.cn-wulanchabu.aliyuncs.com/sas_test/huxin-test-001:nuxeo6-conta****\n",
"ImageDigest": "8f0fbdb41d3d1ade4ffdf21558443f4c03342010563bb8c43ccc09594d507012",
"InstanceName": "testInstance",
"InternetIp": "1.2.XX.XX",
"IntranetIp": "172.19.XX.XX",
"LastTs": 1631779996000,
"Layers": [
"[\"null\"]"
],
"MaliciousSource": "agentless",
"ModifyTs": 1580808765000,
"Name": "debian:10:CVE-2019-9893",
"Namespace": "test-002\n",
"Necessity": "asap",
"Pod": "22222-7xsqq\n",
"PrimaryId": 782661,
"Related": "CVE-2019-9893",
"RepoName": "varnish",
"RepoNamespace": "default",
"RuleTag": "AI",
"ScanTime": 1649814050000,
"Status": 1,
"Tag": "oval",
"TargetId": "m-bp17m0pc0xprzbwo****",
"TargetName": "source-test-obj-XM0Ma",
"TargetType": "ECS_IMAGE",
"Type": "cve",
"Uuid": "0004a32a0305a7f6ab5ff9600d47****"
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | RdCheckNoPermission | Resource directory account verification has no permission. | |
| 500 | ServerError | ServerError | |
| 500 | RdCheckInnerError | Resource directory account service internal error. | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.