docker镜像安全扫描工具--grype

190阅读 0评论2024-07-02 badb0y
分类:系统运维

下载:
anchore/grype

使用:
./grype emqx/emqx
结果如下:

点击(此处)折叠或打开

  1. [root@k8s01 ~]# ./grype emqx/emqx
  2. ? Vulnerability DB [updated]
  3. ? Pulled image
  4. ? Loaded image emqx/emqx:latest
  5. ? Parsed image sha256:0ef9bc19d70ec1e5d1a32ac2aa57eb2f1057e19c3f7bccb3c37b300b57480560
  6. ? Cataloged contents 06fcaf955f399828221cf2ff879aa4e831ef9c6464d6d16a0337cc45e2028db1
  7. ├── ? Packages [26 packages]
  8. ├── ? File digests [312 files]
  9. ├── ? File metadata [312 locations]
  10. └── ? Executables [97 executables]
  11. ? Scanned for vulnerabilities [92 vulnerability matches]
  12. ├── by severity: 10 critical, 35 high, 41 medium, 2 low, 0 negligible (7 unknown)
  13. └── by status: 15 fixed, 80 not-fixed, 0 ignored
  14. NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
  15. busybox 1.31.1-r21 apk CVE-2022-48174 Critical
  16. busybox 1.31.1-r21 1.31.1-r22 apk CVE-2022-28391 High
  17. curl 7.79.1-r0 apk CVE-2023-23914 Critical
  18. curl 7.79.1-r0 apk CVE-2022-32221 Critical
  19. curl 7.79.1-r0 apk CVE-2022-32207 Critical
  20. curl 7.79.1-r0 apk CVE-2023-28319 High
  21. curl 7.79.1-r0 apk CVE-2023-27534 High
  22. curl 7.79.1-r0 apk CVE-2023-27533 High
  23. curl 7.79.1-r0 apk CVE-2022-43551 High
  24. curl 7.79.1-r0 apk CVE-2022-42916 High
  25. curl 7.79.1-r0 apk CVE-2022-42915 High
  26. curl 7.79.1-r0 apk CVE-2022-27782 High
  27. curl 7.79.1-r0 apk CVE-2022-27781 High
  28. curl 7.79.1-r0 7.79.1-r1 apk CVE-2022-27775 High
  29. curl 7.79.1-r0 7.79.1-r1 apk CVE-2022-22576 High
  30. curl 7.79.1-r0 apk CVE-2023-46218 Medium
  31. curl 7.79.1-r0 apk CVE-2023-28321 Medium


上一篇:nginx + lua收集网站状态码
下一篇:openvpn android证书报错