You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure中查看各容器镜像对应的漏洞信息?

解决办法

1. 使用Azure CLI定向查询单个镜像漏洞

通过Azure CLI的容器注册表漏洞扫描命令,可直接获取指定镜像的全量漏洞信息:

  • 若镜像未完成自动扫描,先手动触发扫描:
    az acr run --registry <你的ACR名称> --cmd "az acr vulnerability scan run --registry <你的ACR名称> --name <镜像名:标签>" /dev/null
    
  • 查看该镜像的漏洞详情,可通过输出参数格式化结果:
    az acr vulnerability scan show --registry <你的ACR名称> --name <镜像名:标签> --query 'vulnerabilities' --output table
    
    结果会按漏洞ID、严重程度、描述等字段清晰展示。

2. 用Defender for Cloud高级搜索实现镜像维度聚合

在Defender for Cloud的高级搜索页面,编写Kusto查询语句,按指定镜像过滤并汇总漏洞:

SecurityRecommendation
| where RecommendationName contains "容器镜像漏洞"
| extend ImageFullName = parse_json(ExtendedProperties).["ImageName"]
| where ImageFullName == "<你的镜像名:标签>"
| project 漏洞ID=parse_json(ExtendedProperties).["CveId"], 严重程度=Severity, 漏洞描述=Description

可根据需求添加修复建议、CVSS评分等字段,满足定制化展示需求。

3. 编写自定义脚本批量处理

若需批量梳理多个镜像的漏洞,可基于Azure SDK编写脚本(以Python为例),实现镜像与漏洞的自动关联:

from azure.identity import DefaultAzureCredential
from azure.mgmt.containerregistry import ContainerRegistryManagementClient

credential = DefaultAzureCredential()
client = ContainerRegistryManagementClient(credential, "<你的订阅ID>")

# 遍历指定ACR下的所有镜像
repos = client.repositories.list("<你的资源组>", "<你的ACR名称>")
for repo in repos:
    tags = client.tags.list("<你的资源组>", "<你的ACR名称>", repo.name)
    for tag in tags:
        image_ref = f"{repo.name}:{tag.name}"
        # 获取该镜像的漏洞扫描结果
        scan_result = client.scan_results.get("<你的资源组>", "<你的ACR名称>", image_ref)
        # 输出镜像及对应漏洞
        print(f"镜像: {image_ref}")
        for vuln in scan_result.vulnerabilities:
            print(f"  - {vuln.name} ({vuln.severity})")

脚本可扩展为生成CSV/JSON格式的报告,方便后续分析。

4. 配置ACR定时任务持续生成报告

创建ACR定时任务,定期扫描所有镜像并生成按镜像分组的漏洞报告,可将报告存储至Azure Blob存储或通过邮件发送,实现自动化的镜像漏洞管理。

内容的提问来源于stack exchange,提问作者Eric Hemmerlin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 13:42:41