Use the ALIYUN::ThreatDetection::VulWhitelist type to add vulnerabilities to a whitelist.
Syntax
{
"Type": "ALIYUN::ThreatDetection::VulWhitelist",
"Properties": {
"TargetInfo": Map,
"Whitelist": Map,
"Reason": String
}
}Properties
Property | Type | Required | Editable | Description | Constraints |
TargetInfo | Map | Yes | Yes | The applicable scope of the vulnerability whitelist. | This parameter is a JSON object with the following fields:
|
Whitelist | Map | Yes | No | Information about the vulnerability to add to the whitelist. | The value is a JSON string with the following fields:
|
Reason | String | No | Yes | The reason for adding the vulnerability to the whitelist. | None |
Return values
Fn::GetAtt
TargetInfo: The applicable scope of the whitelist.
VulWhitelistId: The ID of the whitelist.
Whitelist: Details of the vulnerability added to the whitelist.
Reason: The reason for adding the vulnerability to the whitelist.
Examples
ROSTemplateFormatVersion: '2015-09-01'
Parameters:
TargetInfo:
Description:
en: |-
The applicable scope of the whitelist. The value of this parameter is in the JSON format and contains the following fields:
* **type**: the type of the applicable scope. Valid values:
* **GroupId**: the ID of a server group.
* **Uuid**: the UUID of a server.
* **uuids**: the UUIDs of servers. The type of this field is string.
* **groupIds**: the IDs of server groups. The type of this field is long.
> If you leave this parameter empty, the applicable scope is all servers. If you set the **type** field to **GroupId**, you must also specify the **groupIds** field. If you set the **type** field to **Uuid**, you must also specify the **uuids** field.
Required: true
Type: Json
Reason:
Type: String
Description:
en: The reason for adding the vulnerability to the whitelist.
Default: Null
Required: false
Whitelist:
Description:
en: |-
Information about the vulnerability to add to the whitelist. The value is a JSON string that contains the following fields:
* **Status**: the status of the vulnerability.
* **GmtLast**: the timestamp when the vulnerability was last detected. Unit: milliseconds.
* **LaterCount**: The number of vulnerabilities with a medium remediation priority.
* **AsapCount**: The number of vulnerabilities with a high remediation priority.
* **Name**: the name of the vulnerability.
* **Type**: the type of the vulnerability. Valid values:
* **cve**: Linux software vulnerability
* **sys**: Windows system vulnerability
* **cms**: Web-CMS vulnerability
* **app**: application vulnerability
* **emg**: urgent vulnerability
* **Related**: The CVE ID of the vulnerability.
* **HandledCount**: the number of handled vulnerabilities.
* **AliasName**: the alias of the vulnerability.
* **RuleModifyTime**: the time when the vulnerability was last disclosed.
* **NntfCount**: The number of vulnerabilities with a low remediation priority.
* **TotalFixCount**: the total number of fixed vulnerabilities.
* **Tags**: The tags added to the vulnerability.
> You can call the [DescribeGroupedVul](~~DescribeGroupedVul~~) operation to query the information about the vulnerability that you want to add to the whitelist.
Required: true
Type: Json
Resources:
ExtensionResource:
Type: ALIYUN::ThreatDetection::VulWhitelist
Properties:
TargetInfo:
Ref: TargetInfo
Reason:
Ref: Reason
Whitelist:
Ref: Whitelist
Outputs:
TargetInfo:
Value:
Fn::GetAtt:
- ExtensionResource
- TargetInfo
Description: The applicable scope of the whitelist.
Reason:
Value:
Fn::GetAtt:
- ExtensionResource
- Reason
Description: The reason for adding the vulnerability to the whitelist.
VulWhitelistId:
Value:
Fn::GetAtt:
- ExtensionResource
- VulWhitelistId
Description: The ID of the whitelist.
Whitelist:
Value:
Fn::GetAtt:
- ExtensionResource
- Whitelist
Description: Information about the vulnerability added to the whitelist.
{
"ROSTemplateFormatVersion": "2015-09-01",
"Parameters": {
"TargetInfo": {
"Description": {
"en": "The applicable scope of the whitelist. The value of this parameter is in the JSON format and contains the following fields:\n* **type**: the type of the applicable scope. Valid values:\n * **GroupId**: the ID of a server group.\n * **Uuid**: the UUID of a server.\n* **uuids**: the UUIDs of servers. The type of this field is string.\n* **groupIds**: the IDs of server groups. The type of this field is long.\n> If you leave this parameter empty, the applicable scope is all servers. If you set the **type** field to **GroupId**, you must also specify the **groupIds** field. If you set the **type** field to **Uuid**, you must also specify the **uuids** field."
},
"Required": true,
"Type": "Json"
},
"Reason": {
"Type": "String",
"Description": {
"en": "The reason for adding the vulnerability to the whitelist."
},
"Default": null,
"Required": false
},
"Whitelist": {
"Description": {
"en": "Information about the vulnerability to add to the whitelist. The value is a JSON string that contains the following fields:\n* **Status**: the status of the vulnerability.\n* **GmtLast**: the timestamp when the vulnerability was last detected. Unit: milliseconds.\n* **LaterCount**: The number of vulnerabilities with a medium remediation priority.\n* **AsapCount**: The number of vulnerabilities with a high remediation priority.\n* **Name**: the name of the vulnerability.\n* **Type**: the type of the vulnerability. Valid values:\n * **cve**: Linux software vulnerability\n * **sys**: Windows system vulnerability\n * **cms**: Web-CMS vulnerability\n * **app**: application vulnerability\n * **emg**: urgent vulnerability\n* **Related**: The CVE ID of the vulnerability.\n* **HandledCount**: the number of handled vulnerabilities.\n* **AliasName**: the alias of the vulnerability.\n* **RuleModifyTime**: the time when the vulnerability was last disclosed.\n* **NntfCount**: The number of vulnerabilities with a low remediation priority.\n* **TotalFixCount**: the total number of fixed vulnerabilities.\n* **Tags**: The tags added to the vulnerability.\n> You can call the [DescribeGroupedVul](~~DescribeGroupedVul~~) operation to query the information about the vulnerability that you want to add to the whitelist."
},
"Required": true,
"Type": "Json"
}
},
"Resources": {
"ExtensionResource": {
"Type": "ALIYUN::ThreatDetection::VulWhitelist",
"Properties": {
"TargetInfo": {
"Ref": "TargetInfo"
},
"Reason": {
"Ref": "Reason"
},
"Whitelist": {
"Ref": "Whitelist"
}
}
}
},
"Outputs": {
"TargetInfo": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"TargetInfo"
]
},
"Description": "The applicable scope of the whitelist."
},
"Reason": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Reason"
]
},
"Description": "The reason for adding the vulnerability to the whitelist."
},
"VulWhitelistId": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"VulWhitelistId"
]
},
"Description": "The ID of the whitelist."
},
"Whitelist": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Whitelist"
]
},
"Description": "Information about the vulnerability added to the whitelist."
}
}
}