如何在Azure中查看各容器镜像对应的漏洞信息?
解决办法
1. 使用Azure CLI定向查询单个镜像漏洞
通过Azure CLI的容器注册表漏洞扫描命令,可直接获取指定镜像的全量漏洞信息:
- 若镜像未完成自动扫描,先手动触发扫描:
az acr run --registry <你的ACR名称> --cmd "az acr vulnerability scan run --registry <你的ACR名称> --name <镜像名:标签>" /dev/null - 查看该镜像的漏洞详情,可通过输出参数格式化结果:
结果会按漏洞ID、严重程度、描述等字段清晰展示。az acr vulnerability scan show --registry <你的ACR名称> --name <镜像名:标签> --query 'vulnerabilities' --output table
2. 用Defender for Cloud高级搜索实现镜像维度聚合
在Defender for Cloud的高级搜索页面,编写Kusto查询语句,按指定镜像过滤并汇总漏洞:
SecurityRecommendation | where RecommendationName contains "容器镜像漏洞" | extend ImageFullName = parse_json(ExtendedProperties).["ImageName"] | where ImageFullName == "<你的镜像名:标签>" | project 漏洞ID=parse_json(ExtendedProperties).["CveId"], 严重程度=Severity, 漏洞描述=Description
可根据需求添加修复建议、CVSS评分等字段,满足定制化展示需求。
3. 编写自定义脚本批量处理
若需批量梳理多个镜像的漏洞,可基于Azure SDK编写脚本(以Python为例),实现镜像与漏洞的自动关联:
from azure.identity import DefaultAzureCredential from azure.mgmt.containerregistry import ContainerRegistryManagementClient credential = DefaultAzureCredential() client = ContainerRegistryManagementClient(credential, "<你的订阅ID>") # 遍历指定ACR下的所有镜像 repos = client.repositories.list("<你的资源组>", "<你的ACR名称>") for repo in repos: tags = client.tags.list("<你的资源组>", "<你的ACR名称>", repo.name) for tag in tags: image_ref = f"{repo.name}:{tag.name}" # 获取该镜像的漏洞扫描结果 scan_result = client.scan_results.get("<你的资源组>", "<你的ACR名称>", image_ref) # 输出镜像及对应漏洞 print(f"镜像: {image_ref}") for vuln in scan_result.vulnerabilities: print(f" - {vuln.name} ({vuln.severity})")
脚本可扩展为生成CSV/JSON格式的报告,方便后续分析。
4. 配置ACR定时任务持续生成报告
创建ACR定时任务,定期扫描所有镜像并生成按镜像分组的漏洞报告,可将报告存储至Azure Blob存储或通过邮件发送,实现自动化的镜像漏洞管理。
内容的提问来源于stack exchange,提问作者Eric Hemmerlin
相关产品推荐
相关产品推荐

