You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何追踪docker scout cves检测出的golang stdlib漏洞来源

问题

我有一个基于Ubuntu 23.04的Docker镜像,运行docker scout cves时发现,pkg:golang/stdlib@1.19.4包中的stdlib 1.19.4存在两个严重漏洞(CVE-2023-24540和CVE-2023-24538)。

我完全不清楚这个包的来源:我并未在自有代码中使用Go语言,在dpkg.log中找不到该包,手动执行所有apt命令也未发现它的踪迹,Docker Desktop的受影响包树中也未找到它(不过也可能容易遗漏)。

除了对Dockerfile进行二分排查直到漏洞消失,有没有系统的方法找出是哪个命令导致该包被安装?

补充说明:提供包含所有安装命令但不含自有代码的Dockerfile:

# Start with a base Ubuntu image
FROM ubuntu:23.04

ARG xdebug

# Prevent any prompts during installation
ENV DEBIAN_FRONTEND noninteractive

# Set up apt with any additional repositories we need
RUN apt-get update
RUN apt-get install -y software-properties-common
RUN add-apt-repository ppa:maxmind/ppa
RUN apt-get update --fix-missing
RUN apt upgrade -y

# Install Apache and various other packages.
RUN apt-get install -y apache2
RUN apt-get install -y vim cron geoipupdate git logrotate mysql-client openssh-server redis rsync supervisor unzip zip
RUN apt-get install -y python3-pip python3-dev python3-setuptools python3-numpy python3-pandas python3-yaml python3-click python3-dotenv python3-mysql.connector python3.tqdm
RUN apt-get install -y gcc make dnsutils ncdu lsof

# Configure any Apache modules that weren't in the default
RUN cp /etc/apache2/mods-available/rewrite.load /etc/apache2/mods-enabled
RUN cp /etc/apache2/mods-available/expires.load /etc/apache2/mods-enabled
RUN cp /etc/apache2/mods-available/authz_groupfile.load /etc/apache2/mods-enabled
RUN cp /etc/apache2/mods-available/headers.load /etc/apache2/mods-enabled/
RUN cp /etc/apache2/mods-available/ssl.load /etc/apache2/mods-enabled
RUN cp /etc/apache2/mods-available/socache_shmcb.load /etc/apache2/mods-enabled
RUN cp /etc/apache2/mods-available/ssl.conf /etc/apache2/mods-enabled

# Suppress Apache warning on being unable to determine the fully qualified domain name
RUN echo "ServerName localhost">>/etc/apache2/apache2.conf

# Install PHP and plumb into Apache
RUN apt-get update --fix-missing
RUN apt-get install -y php8.1 php8.1-curl php8.1-gd php8.1-gettext php8.1-gmp php8.1-iconv php8.1-imap php8.1-intl php8.1-mbstring php8.1-mysql php8.1-oauth php8.1-redis php8.1-xml php8.1-yaml php8.1-zip
RUN if [ "$xdebug" = "with" ] ; then apt-get install -y php8.1-xdebug ; fi
RUN apt-get install -y libapache2-mod-php8.1

# The bcmath extension seems to have problems when installed in line with the other PHP modules, as of 2022-07-18
RUN apt-get update --fix-missing
RUN apt-get install -y php8.1-bcmath

# Install locales
RUN apt-get install -y locales
RUN locale-gen en_GB
RUN locale-gen en_GB.UTF-8
RUN locale-gen de_DE
RUN locale-gen de_DE.UTF-8
RUN locale-gen es_ES
RUN locale-gen es_ES.UTF-8
RUN locale-gen fr_FR
RUN locale-gen fr_FR.UTF-8
RUN locale-gen it_IT
RUN locale-gen it_IT.UTF-8
RUN update-locale
系统排查方法
  • 步骤1:定位镜像内Go相关文件
    先确认镜像中是否存在Go相关文件,运行以下命令:

    docker run --rm <你的镜像名> find / -name "go" -type f 2>/dev/null
    docker run --rm <你的镜像名> find / -path "*golang/stdlib*" 2>/dev/null
    

    若找到文件,记录路径,可辅助溯源。

  • 步骤2:追踪APT依赖链
    部分包可能将Go作为构建依赖(非运行依赖),可通过以下方式排查:

    1. 在镜像内安装依赖分析工具:docker run --rm <你的镜像名> apt-get install -y apt-rdepends
    2. 对可疑包逐一检查反向依赖:docker run --rm <你的镜像名> apt-rdepends -r <包名> | grep -i golang,可优先排查geoipupdate(来自PPA源)、git、redis等包
    3. 查看APT操作日志:docker run --rm <你的镜像名> cat /var/log/apt/history.log | grep -i golang,日志会记录所有APT安装的包列表
  • 步骤3:在Dockerfile中添加阶段检查
    给每个RUN安装命令追加Go包检查,无需二分法即可定位触发步骤:

    RUN apt-get install -y apache2 && echo "After installing apache2:" && dpkg -l | grep -i golang || echo "No golang packages"
    

    构建时每一步都会输出是否已安装Go相关包,直接定位到触发安装的命令。

  • 步骤4:单独测试PPA源的影响
    你添加了ppa:maxmind/ppa源,可单独验证该源是否引入Go依赖:
    构建测试镜像:

    FROM ubuntu:23.04
    ENV DEBIAN_FRONTEND noninteractive
    RUN apt-get update && apt-get install -y software-properties-common
    RUN add-apt-repository ppa:maxmind/ppa && apt-get update
    RUN apt-get install -y geoipupdate && dpkg -l | grep -i golang
    

    运行构建,查看是否会安装Go相关包。

  • 步骤5:分析Docker Scout的SBOM报告
    Docker Scout可能检测的是文件层面的Go标准库(而非dpkg注册的包),生成完整SBOM并搜索:

    docker scout sbom <你的镜像名> | grep -B2 -A2 "golang/stdlib"
    

    查看关联的组件(如某个Go编译的二进制文件),从而找到来源。

内容的提问来源于stack exchange,提问作者xgretsch

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 03:57:02