Files
shuffle-cracked/app_gen/openapi-parsers/other/TIO-API-Container-Security-v2.json
T
2020-05-11 19:17:35 +02:00

1 line
36 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{"openapi":"3.0.0","info":{"title":"Container Security v2","description":"Container Security API provides the endpoints for securing container images, for example, Docker. Using the API, you can you seamlessly and securely enable DevOps processes by providing visibility into the security of container images including vulnerabilities, malware and policy violations through integration with the build process.\n\nFor background information about managing container security, see the [documentation site](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/Welcome.htm).","version":"1.0.0"},"security":[{"cloud":[]}],"tags":[{"name":"Images","description":"With the Tenable.io Container Security images API, you can get a filtered list of available images, as well as the details of an individual image.\n\nFor background information, see [Tenable.io Container Security User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/Welcome.htm)."},{"name":"Repositories","description":"With the Tenable.io Container Security repositories API, you can get a filtered list of available image repositories, as well as the details of an individual repository.\n\nFor background information, see [Tenable.io Container Security User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/ManageImageRepositories.htm)."},{"name":"Reports","description":"With the Tenable.io Container security reports API, you can get a detailed vulnerability scan report for an image.\n\nFor background information, see [Tenable.io Container Security User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/ViewScanResults.htm)."}],"servers":[{"url":"https://cloud.tenable.com/container-security/api/v2/"}],"paths":{"/images":{"get":{"tags":["Images"],"operationId":"container-security-v2-list-images","summary":"List images","description":"Returns a paginated list of images. Use URL query parameters to filter the list. <p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","parameters":[{"in":"query","name":"offset","required":false,"schema":{"type":"integer","minimum":0,"default":0},"description":"The number of skipped records in the returned result set. Must be in the int32 format."},{"in":"query","name":"limit","required":false,"schema":{"type":"integer","minimum":1,"maximum":1000,"default":50},"description":"The number of records to include in the result set. Must be in the int32 format. Default is 50. The maximum limit is 1,000."},{"in":"query","name":"name","schema":{"type":"string"},"description":"The image name to filter on. Tenable.io returns only the images with names that exactly match the parameter value. The value is case-sensitive."},{"in":"query","name":"repo","schema":{"type":"string"},"description":"The repository name to filter on. Tenable.io returns only the images from repositories that exactly match the parameter value. The value is case-sensitive."},{"in":"query","name":"tag","schema":{"type":"string"},"description":"The tag to filter on. Tenable.io returns only the images with tags that exactly match the parameter value. The value is case-sensitive."},{"in":"query","name":"hasMalware","schema":{"type":"boolean"},"description":"Specifies whether to return only the images with associated malware (images with the `numberOfMalware` attribute greater than 0)."},{"in":"query","name":"score","schema":{"type":"integer"},"description":"The score to filter on. Tenable.io limits results based on the parameter value and the comparison operator specified by the `scoreOperator` parameter. For more information about the risk score metric, see [Tenable.io Vulnerability Management User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/RiskMetrics.htm)."},{"in":"query","name":"scoreOperator","description":"The comparison operator for the value specified by the `score` parameter. Operators include:\n - EQ—equals\n - GT—greater than\n - EQ—less than","schema":{"type":"string","enum":["EQ","LT","GT"]}},{"in":"query","name":"os","schema":{"type":"string"},"description":"The operating system to filter on. Tenable.io returns only the images with an operating system that exactly matches the parameter value."}],"responses":{"200":{"description":"Returns a paginated list of images in your Tenable.io Container Security instance.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/imageListResponse"},"examples":{"response":{"value":{"items":[{"repoId":"2491620318530539587","repoName":"dmjb","name":"jboss","tag":"latest","digest":"sha256:f75748b2bbd5a386c8d876770ff09a65c42335fb1f538025b928c794ffa8123f","hasReport":false,"hasInventory":false,"status":"scan_failed","lastJobStatus":"failed","pullCount":"0","pushCount":"1","source":"pushed","createdAt":"2019-04-19T11:31:11.283Z","updatedAt":"2019-04-19T12:33:29.903Z","finishedAt":"2019-04-19T12:33:29.903Z","imageHash":"859c02589af7","size":"4471","layers":[{"size":133212385,"digest":"sha256:01e684a89bbea67a11fcc96caed8e8b3320c44e29c2ab2a85016f48a69870bc8"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":3338,"digest":"sha256:ebdaef68b4f08d23189ae32fd90bd68261385549f46360d9c3d163b988d91a45"},{"size":250,"digest":"sha256:cc7ec6c68bd72324ab932dc00474d0713044542c2adf6bff6f4e4d1cacc70737"},{"size":510,"digest":"sha256:01bb3ac59edc6a05e14a5151cdc39eae261ff37a933118063d1f91bb14aaceb4"},{"size":7863072,"digest":"sha256:a248b0871c3cac9ce2b2a956e118ce03e49027d5d4c4da74df00ae399fff17c3"},{"size":681,"digest":"sha256:c9f371853f28eb40b76f309e27f671b57bffb8d80df4ca8e7970885ae532e172"},{"size":86733990,"digest":"sha256:2fe0df338fc0cc7d9ec4428ba7538f165f901f3a7760c7fecbdda11a435c5eee"},{"size":71511,"digest":"sha256:aa2f8df214335759614f9aceea51f570354944f59c36cc8399415bbfab91839e"},{"size":67494686,"digest":"sha256:23efb549476f5f10a40b3784758a807c0194d87a0b18c9a5a3436e67611e971b"},{"size":421,"digest":"sha256:1049dfc2ba444c2f74f3eb77a07d0fd5fe304d79ea7178d5a0885788696d63aa"},{"size":374,"digest":"sha256:ef072d3c9b418ba3ce624ce456d311bb81c9ae5d4d5bc682da5edadde408fce7"}],"os":"Unknown","osVersion":"Unknown"},{"repoId":"7185635748924628551","repoName":"elastic","name":"elasticsearch","tag":"5","digest":"sha256:0278ed727ad6dd0bef0be279b3112755a110980c31f07e7f4a54e19b9ca2e24a","hasReport":true,"hasInventory":false,"status":"scanned","lastJobStatus":"completed","score":10,"numberOfVulns":54,"numberOfMalware":0,"pullCount":"0","pushCount":"1","source":"on_prem_import","createdAt":"2018-12-13T17:51:03.295Z","updatedAt":"2019-05-14T10:48:02.857Z","finishedAt":"2019-05-14T10:48:02.857Z","imageHash":"5e9d896dc62c","size":"3460","layers":[],"os":"Debian","osVersion":"9.5"},{"repoId":"7185635748924628551","repoName":"postgres_db","name":"postgres","tag":"latest","digest":"sha256:0dec082064d1203a3ead704057de56823d2c8ae11818da0fd3065dee9ec1b92e","hasReport":true,"hasInventory":false,"status":"scanned","lastJobStatus":"completed","score":10,"numberOfVulns":46,"numberOfMalware":0,"pullCount":"0","pushCount":"1","source":"on_prem_import","createdAt":"2018-12-13T17:51:43.861Z","updatedAt":"2019-05-14T16:46:10.739Z","finishedAt":"2019-05-14T16:46:10.739Z","imageHash":"c230b2f564da","size":"3244","layers":[],"os":"Debian","osVersion":"9.6"}],"pagination":{"offset":0,"limit":1000,"total":138,"sort":[]}}}}}}},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."}}}},"/images/{repository}/{image}/{tag}":{"get":{"tags":["Images"],"summary":"Get image details","operationId":"container-security-v2-get-image-details","description":"Returns the details for an image specified by repository, name, and tag.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","parameters":[{"name":"repository","in":"path","description":"The name of the Tenable.io Container Security repository where the image is stored. The value is case-sensitive.","required":true,"schema":{"type":"string"}},{"name":"image","in":"path","required":true,"schema":{"type":"string"},"description":"The name of the image. The value is case-sensitive."},{"name":"tag","in":"path","required":true,"description":"The tag identifying the image version. The value is case-sensitive.\n**Note**: Image tags are not equivalent to Tenable.io [asset tags](/reference#tags).","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns the image details.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/imageDetails"},"examples":{"response":{"value":{"name":"jboss","repository":"dmjb","tag":"latest","digest":"sha256:f75748b2bbd5a386c8d876770ff09a65c42335fb1f538025b928c794ffa8123f","uploadedAt":"2019-04-19T11:31:11.283Z","lastScanned":"2019-04-19T12:33:29.903Z","status":"scan_failed","size":"4471","layers":[{"size":133212385,"digest":"sha256:01e684a89bbea67a11fcc96caed8e8b3320c44e29c2ab2a85016f48a69870bc8"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":32,"digest":"sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"},{"size":3338,"digest":"sha256:ebdaef68b4f08d23189ae32fd90bd68261385549f46360d9c3d163b988d91a45"},{"size":250,"digest":"sha256:cc7ec6c68bd72324ab932dc00474d0713044542c2adf6bff6f4e4d1cacc70737"},{"size":510,"digest":"sha256:01bb3ac59edc6a05e14a5151cdc39eae261ff37a933118063d1f91bb14aaceb4"},{"size":7863072,"digest":"sha256:a248b0871c3cac9ce2b2a956e118ce03e49027d5d4c4da74df00ae399fff17c3"},{"size":681,"digest":"sha256:c9f371853f28eb40b76f309e27f671b57bffb8d80df4ca8e7970885ae532e172"},{"size":86733990,"digest":"sha256:2fe0df338fc0cc7d9ec4428ba7538f165f901f3a7760c7fecbdda11a435c5eee"},{"size":71511,"digest":"sha256:aa2f8df214335759614f9aceea51f570354944f59c36cc8399415bbfab91839e"},{"size":67494686,"digest":"sha256:23efb549476f5f10a40b3784758a807c0194d87a0b18c9a5a3436e67611e971b"},{"size":421,"digest":"sha256:1049dfc2ba444c2f74f3eb77a07d0fd5fe304d79ea7178d5a0885788696d63aa"},{"size":374,"digest":"sha256:ef072d3c9b418ba3ce624ce456d311bb81c9ae5d4d5bc682da5edadde408fce7"}]}}}}}},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."},"404":{"description":"Returned if Tenable.io cannot find the specified image."}}},"delete":{"tags":["Images"],"summary":"Delete image","description":"Deletes an image specified by repository, name, and tag.<p>Requires SCAN OPERATOR [24] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"container-security-v2-delete-image","parameters":[{"name":"repository","in":"path","description":"The name of the Tenable.io Container Security repository where the image is stored. The value is case-sensitive.","required":true,"schema":{"type":"string"}},{"name":"image","in":"path","required":true,"schema":{"type":"string"},"description":"The name of the image. The value is case-sensitive."},{"name":"tag","in":"path","required":true,"description":"The tag identifying the image version. The value is case-sensitive.\n**Note**: Image tags are not equivalent to Tenable.io [asset tags](/reference#tags).","schema":{"type":"string"}}],"responses":{"204":{"description":"Returned if Tenable.io successfully deletes the specified image."},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."},"404":{"description":"Returned if Tenable.io cannot find the specified image."}}}},"/repositories":{"get":{"tags":["Repositories"],"operationId":"container-security-v2-list-repositories","summary":"List repositories","description":"Returns a list of image repositories in your Tenable.io Container Security instance. Use the query parameters to filter the list. <p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","parameters":[{"name":"imageName","in":"query","required":false,"schema":{"type":"string"},"description":"The repository name to filter on. Tenable.io Container Security returns only the repositories with names that exactly match the parameter value. The value is case-sensitive."},{"name":"nameContains","in":"query","required":false,"schema":{"type":"string"},"description":"The partial repository name to filter on. Tenable.io Container Security returns the images with names that contain the parameter value. The value is case-sensitive."},{"in":"query","name":"offset","required":false,"schema":{"type":"integer","minimum":0,"default":0},"description":"The number of skipped records in the returned result set. Must be in the int32 format."},{"in":"query","name":"limit","required":false,"schema":{"type":"integer","minimum":1,"maximum":1000,"default":50},"description":"The number of records to include in the result set. Must be in the int32 format. Default is 50. The maximum limit is 1,000."}],"responses":{"200":{"description":"success","content":{"application/json":{"schema":{"$ref":"#/components/schemas/repositoryListResponse"},"examples":{"response":{"value":{"items":[{"name":"dmjb","imagesCount":6,"labelsCount":6,"vulnerabilitiesCount":792,"malwareCount":0,"pullCount":0,"pushCount":12,"totalBytes":1766950068},{"name":"air-gap","imagesCount":7,"labelsCount":7,"vulnerabilitiesCount":514,"malwareCount":0,"pullCount":0,"pushCount":0,"totalBytes":0},{"name":"imiell","imagesCount":1,"labelsCount":1,"vulnerabilitiesCount":291,"malwareCount":0,"pullCount":0,"pushCount":2,"totalBytes":403346467}],"pagination":{"offset":0,"limit":10,"total":3,"sort":[]}}}}}}},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."}}}},"/repositories/{name}":{"get":{"tags":["Repositories"],"operationId":"container-security-v2-get-repository-details","summary":"Get repository details","description":"Returns details for a Tenable.io Container Security repository.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","parameters":[{"name":"name","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"Returns the repository details.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/repositoryDetails"},"examples":{"response":{"value":{"name":"dmjb","imagesCount":6,"labelsCount":6,"vulnerabilitiesCount":842,"malwareCount":0,"pullCount":0,"pushCount":12,"totalBytes":1766950068}}}}}},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."},"404":{"description":"Returned if Tenable.io cannot find the specified repository."}}},"delete":{"tags":["Repositories"],"summary":"Delete repository","description":"Deletes a Tenable.io Container Security repository.<p>Requires SCAN OPERATOR [24] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","operationId":"container-security-v2-delete-repository","parameters":[{"name":"name","in":"path","required":true,"schema":{"type":"string"},"description":"The name of the repository to delete."}],"responses":{"204":{"description":"Returned if Tenable.io successfully deletes the specified repository."},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."},"404":{"description":"Returned if Tenable.io cannot find the specified repository."}}}},"/reports/{repository}/{image}/{tag}":{"get":{"tags":["Reports"],"operationId":"container-security-v2-get-image-report","summary":"Get image report","description":"Returns a vulnerability report for the specified image.<p>Requires BASIC [16] user permissions. See <a href=\"/docs/permissions\">Permissions</a>.</p>","parameters":[{"name":"repository","in":"path","description":"The name of the Tenable.io Container Security repository where the image is stored. The value is case-sensitive.","required":true,"schema":{"type":"string"}},{"name":"image","in":"path","required":true,"schema":{"type":"string"},"description":"The name of the image. The value is case-sensitive."},{"name":"tag","in":"path","required":true,"description":"The tag identifying the image version. The value is case-sensitive.\n**Note**: Image tags are not equivalent to Tenable.io [asset tags](/reference#tags).","schema":{"type":"string"}}],"responses":{"200":{"description":"Returns a vulnerability scan report for the image.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/imageReport"},"examples":{"response":{"value":{"os_release_name":"16.04.2 LTS (Xenial Xerus)","malware":[{"file":"/20131116130541_http___198_2_192_204_22_disknyp","type":"ELF32","md5":"c92129fc230bacd113530fee254fc2b6","sha256":"sha256:60e24cb19a3cfdc88712f3511adfde242abff3c1915b34eeb19dd7cc72380df2"},{"file":"/20131103183232_http___61_132_227_111_8080_meimei","type":"ELF32","md5":"27072fd3a3cedaeed8cfebf29b9ed73f","sha256":"sha256:a8cd37210dea08880122c360cd096eda872f443c3dd39e498b2695955a3e0ad7"},{"file":"/20131116163507_http___198_2_192_204_22_disknyp","type":"ELF32","md5":"c92129fc230bacd113530fee254fc2b6","sha256":"sha256:60e24cb19a3cfdc88712f3511adfde242abff3c1915b34eeb19dd7cc72380df2"}],"sha256":"sha256:f708f91abdec052d05a46213815540616d24627b6af9cb3668484efb017969bf","os":"LINUX_UBUNTU","risk_score":10,"findings":[{"nvdFinding":{"cve":"CVE-2018-0494","description":"2018/05/09","published_date":"2018/05/09","modified_date":"It was discovered that Wget incorrectly handled certain inputs. An\nattacker could possibly use this to inject arbitrary cookie values.\n\nNote that Tenable Network Security has extracted the preceding\ndescription block directly from the Ubuntu security advisory. Tenable\nhas attempted to automatically clean and format it as much as possible\nwithout introducing additional issues.","cvss_score":"4.3","access_vector":"Network","access_complexity":"Medium","auth":"None required","availability_impact":"None","confidentiality_impact":"None","integrity_impact":"Partial","cwe":"CWE-20","cpe":["p-cpe:/a:canonical:ubuntu_linux:wget"],"remediation":"Update the affected wget package.","references":["USN:3643-1"]},"packages":[{"name":"wget","version":"1.17.1-1ubuntu1.2","type":"linux"}]},{"nvdFinding":{"cve":"CVE-2017-15670","description":"2018/01/17","published_date":"2018/01/17","modified_date":"It was discovered that the GNU C library did not properly handle all\nof the possible return values from the kernel getcwd(2) syscall. A\nlocal attacker could potentially exploit this to execute arbitrary\ncode in setuid programs and gain administrative privileges.\n(CVE-2018-1000001)\n\nA memory leak was discovered in the _dl_init_paths() function in the\nGNU C library dynamic loader. A local attacker could potentially\nexploit this with a specially crafted value in the LD_HWCAP_MASK\nenvironment variable, in combination with CVE-2017-1000409 and another\nvulnerability on a system with hardlink protections disabled, in order\nto gain administrative privileges. (CVE-2017-1000408)\n\nA heap-based buffer overflow was discovered in the _dl_init_paths()\nfunction in the GNU C library dynamic loader. A local attacker could\npotentially exploit this with a specially crafted value in the\nLD_LIBRARY_PATH environment variable, in combination with\nCVE-2017-1000408 and another vulnerability on a system with hardlink\nprotections disabled, in order to gain administrative privileges.\n(CVE-2017-1000409)\n\nAn off-by-one error leading to a heap-based buffer overflow was\ndiscovered in the GNU C library glob() implementation. An attacker\ncould potentially exploit this to cause a denial of service or execute\narbitrary code via a maliciously crafted pattern. (CVE-2017-15670)\n\nA heap-based buffer overflow was discovered during unescaping of user\nnames with the ~ operator in the GNU C library glob() implementation.\nAn attacker could potentially exploit this to cause a denial of\nservice or execute arbitrary code via a maliciously crafted pattern.\n(CVE-2017-15804)\n\nIt was discovered that the GNU C library dynamic loader mishandles\nRPATH and RUNPATH containing $ORIGIN for privileged (setuid or\nAT_SECURE) programs. A local attacker could potentially exploit this\nby providing a specially crafted library in the current working\ndirectory in order to gain administrative privileges. (CVE-2017-16997)\n\nIt was discovered that the GNU C library malloc() implementation could\nreturn a memory block that is too small if an attempt is made to\nallocate an object whose size is close to SIZE_MAX, resulting in a\nheap-based overflow. An attacker could potentially exploit this to\ncause a denial of service or execute arbitrary code. This issue only\naffected Ubuntu 17.10. (CVE-2017-17426).\n\nNote that Tenable Network Security has extracted the preceding\ndescription block directly from the Ubuntu security advisory. Tenable\nhas attempted to automatically clean and format it as much as possible\nwithout introducing additional issues.","cvss_score":"7.5","access_vector":"Network","access_complexity":"Medium","auth":"None required","availability_impact":"Complete","confidentiality_impact":"Complete","integrity_impact":"Complete","cwe":"CWE-119","cpe":["p-cpe:/a:canonical:ubuntu_linux:libc6"],"remediation":"Update the affected libc6 package.","references":["USN:3534-1"]},"packages":[{"name":"libc6","version":"2.23-0ubuntu9","type":"linux"}]},{"nvdFinding":{"cve":"CVE-2017-13089","description":"2017/10/26","published_date":"2017/10/26","modified_date":"Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that\nWget incorrectly handled certain HTTP responses. A remote attacker\ncould use this issue to cause Wget to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2017-13089,\nCVE-2017-13090)\n\nDawid Golunski discovered that Wget incorrectly handled recursive or\nmirroring mode. A remote attacker could possibly use this issue to\nbypass intended access list restrictions. (CVE-2016-7098)\n\nOrange Tsai discovered that Wget incorrectly handled CRLF sequences in\nHTTP headers. A remote attacker could possibly use this issue to\ninject arbitrary HTTP headers. (CVE-2017-6508).\n\nNote that Tenable Network Security has extracted the preceding\ndescription block directly from the Ubuntu security advisory. Tenable\nhas attempted to automatically clean and format it as much as possible\nwithout introducing additional issues.","cvss_score":"9.3","access_vector":"Network","access_complexity":"Medium","auth":"None required","availability_impact":"Complete","confidentiality_impact":"Complete","integrity_impact":"Complete","cwe":"CWE-119","cpe":["p-cpe:/a:canonical:ubuntu_linux:wget"],"remediation":"Update the affected wget package.","references":["USN:3464-1"]},"packages":[{"name":"wget","version":"1.17.1-1ubuntu1.2","type":"linux"}]}],"os_version":"16.04","created_at":"2018-09-17T17:07:34.556Z","installed_packages":[{"name":"dpkg","version":"1.18.4ubuntu1.2","type":"linux"},{"name":"ubuntu-keyring","version":"2012.05.19","type":"linux"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.8","type":"linux"},{"name":"libcap2-bin","version":"1:2.24-12","type":"linux"},{"name":"liblz4-1","version":"0.0~r131-2ubuntu2","type":"linux"}],"platform":"docker","image_name":"ubuntu","updated_at":"2019-05-16T11:04:20.301Z","digest":"f708f91abdec052d05a46213815540616d24627b6af9cb3668484efb017969bf","tag":"infected","potentially_unwanted_programs":[],"docker_image_id":"4013750e4cd5","os_architecture":"AMD64"}}}}}},"401":{"description":"Returned if Tenable.io cannot authenticate the user account that submitted the request."},"404":{"description":"Returned if Tenable.io cannot find the specified image or the report for the image is not ready."}}}}},"components":{"securitySchemes":{"cloud":{"type":"apiKey","in":"header","name":"X-ApiKeys","description":"Format - accessKey=ACCESS_KEY;secretKey=SECRET_KEY"}},"schemas":{"imageListResponse":{"type":"object","description":"A list of images with pagination information.","properties":{"pagination":{"$ref":"#/components/schemas/pagination"},"items":{"type":"array","items":{"$ref":"#/components/schemas/imageDetails"}}}},"imageDetails":{"type":"object","description":"The image details.","properties":{"name":{"type":"string","description":"The name of the image."},"repository":{"type":"string","description":"The name of the Tenable.io Container Security repository where the image is stored."},"tag":{"type":"string","description":"The tag identifying the image version.\n**Note**: Image tags are not equivalent to Tenable.io [asset tags](/reference#tags)."},"digest":{"type":"string","description":"A content-addressable image identifier."},"status":{"type":"string","description":"The image analysis status. Status values can include:\n - never_scanned\n - scanned\n - scan_failed","enum":["never_scanned","scanned","scan_failed"]},"score":{"type":"number","format":"double","description":"The image risk score. For more information about the risk score metric, see [Tenable.io Vulnerability Management User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/RiskMetrics.htm)."},"numberOfVulns":{"type":"integer","format":"int32","description":"The number of known vulnerabilities for the image."},"numberOfMalware":{"type":"integer","format":"int32","description":"The number of known malware exploits for image."},"uploadedAt":{"type":"string","description":"An ISO timestamp indicating the date and time when the image was uploaded to Tenable.io Container Security, for example, `2018-12-31T13:51:17.243Z`."},"lastScanned":{"type":"string","description":"An ISO timestamp indicating the date and time when Tenable.io Container Security last scanned the image, for example, `2018-12-31T13:51:17.243Z`."},"layers":{"type":"array","description":"The layers that represent the history of changes to the image.","items":{"$ref":"#/components/schemas/layer"}},"reportUrl":{"type":"string","description":"The URL of the latest available image analysis report."}}},"layer":{"type":"object","description":"Detailed information for an image layer.","properties":{"size":{"type":"number","format":"long","description":"The layer size in kilobytes."},"digest":{"type":"string","description":"A content-addressable layer identifier."}}},"repositoryListResponse":{"type":"object","description":"A list of Tenable.io Container Security repositories with pagination information.","properties":{"pagination":{"$ref":"#/components/schemas/pagination"},"items":{"type":"array","items":{"$ref":"#/components/schemas/repositoryDetails"}}}},"repositoryDetails":{"type":"object","description":"Details of a Tenable.io Container Security repository.","properties":{"name":{"type":"string","description":"The name of the repository."},"description":{"type":"string","description":"The description of the repository."},"imagesCount":{"type":"integer","format":"int64","description":"The total number of images in the repository."},"labelsCount":{"type":"integer","format":"int64","description":"The number of unique image name/tag combinations in the repository."},"vulnerabilitiesCount":{"type":"integer","format":"int64","description":"The total number of discovered vulnerabilities for the images in the repository."},"malwareCount":{"type":"integer","format":"int64","description":"The total number of known malware exploits for the images in the repository."},"pullCount":{"type":"integer","format":"int64","description":"The number of times the image was pulled from the repository."},"pushCount":{"type":"integer","format":"int64","description":"The number of times the image was uploaded to the repository"},"totalBytes":{"type":"integer","format":"int64","description":"The total size in bytes of the images in the repository."}},"required":["name","imagesCount","labelsCount","vulnerabilitiesCount","malwareCount","pullCount","pushCount","totalBytes"]},"imageReport":{"type":"object","description":"An image vulnerability report.","properties":{"os_release_name":{"type":"string","description":"The image operating system release name."},"malware":{"type":"array","description":"A list of malware files identified by the Tenable.io Container Security scan in the image.","items":{"$ref":"#/components/schemas/malware"},"uniqueItems":true},"sha256":{"type":"string","description":"The image SHA256 hash."},"os":{"type":"string","description":"The image operating system."},"risk_score":{"type":"integer","description":"The image risk score on a scale of 1-10. For more information about the risk score metric, see [Tenable.io Vulnerability Management User Guide](https://docs.tenable.com/cloud/containersecurity/Content/ContainerSecurity/RiskMetrics.htm)."},"findings":{"type":"array","description":"A list of vulnerabilities that Tenable.io Container Security identified in the image.","items":{"$ref":"#/components/schemas/finding"},"uniqueItems":true},"os_version":{"type":"string","description":"The image operating system version."},"created_at":{"type":"string","format":"date-time","description":"An ISO timestamp indicating the date and time when the image was created, for example, `2018-12-31T13:51:17.243Z`."},"installed_packages":{"type":"array","description":"A list of installed software packages for the image.","items":{"$ref":"#/components/schemas/installedPackage"}},"platform":{"type":"string","description":"The image platform, for example, `docker`."},"image_name":{"type":"string","description":"The name of the image."},"updated_at":{"type":"string","format":"date-time","description":"An ISO timestamp indicating the date and time when the image was last uploaded, for example, `2018-12-31T13:51:17.243Z`."},"digest":{"type":"string","description":"The image digest."},"tag":{"type":"string","description":"The tag identifying the image version.\n**Note**: Image tags are not equivalent to Tenable.io [asset tags](/reference#tags)."},"potentially_unwanted_programs":{"type":"array","description":"A list of potentially unwanted programs for the image.","items":{"$ref":"#/components/schemas/unwantedProgram"},"uniqueItems":true},"docker_image_id":{"type":"string","description":"The image Docker ID."},"os_architecture":{"type":"string","description":"An image processor architecture, for example, `AMD64`."}},"required":["name","imagesCount","labelsCount","vulnerabilitiesCount","malwareCount","pullCount","pushCount","totalBytes"]},"finding":{"type":"object","description":"The details for the discovered vulnerability and a list of associated software packages.","properties":{"nvdFinding":{"$ref":"#/components/schemas/nvdFinding"},"packages":{"type":"array","items":{},"uniqueItems":true}}},"nvdFinding":{"type":"object","description":"The details for the discovered vulnerability, including description, external references, and remediation information.","properties":{"cve":{"type":"string","description":"The Common Vulnerabilities and Exposures (CVE) ID for vulnerability."},"description":{"type":"string","description":"The extended description of the vulnerability."},"published_date":{"type":"string","description":"An ISO timestamp indicating the date when the vulnerability definition was published, for example, `2018-12-31T13:51:17.243Z`."},"modified_date":{"type":"string","description":"An ISO timestamp indicating the date when the vulnerability definition was updated, for example, `2018-12-31T13:51:17.243Z`."},"cvss_score":{"type":"string","description":"The CVSSv2 base score (intrinsic and fundamental characteristics of a vulnerability that are constant over time and user environments)."},"access_vector":{"type":"string","description":"The CVSSv2 Access Vector (AV) metric for the vulnerability indicating how the vulnerability can be exploited. Possible values include:\n - Local\n - Adjacent Network\n - Network"},"access_complexity":{"type":"string","description":"The CVSSv2 Access Complexity (AC) metric for the vulnerability. Possible values include:\n - High\n - Medium\n - Low"},"auth":{"type":"string","description":"The CVSSv2 Authentication (Au) metric for the vulnerability. The metric describes the number of times that an attacker must authenticate to a target to exploit it. Possible values include:\n - None required\n - Single\n - Multiple"},"availability_impact":{"type":"string","description":"The CVSSv2 availability impact metric for the vulnerability. The metric describes the impact on the availability of the target system. Possible values include:\n - None\n - Partial\n - Complete"},"confidentiality_impact":{"type":"string","description":"The CVSSv2 confidentiality impact metric for the vulnerability. The metric describes the impact on the confidentiality of data processed by the system. Possible values include:\n - None\n - Partial\n - Complete"},"integrity_impact":{"type":"string","description":"The CVSSv2 integrity impact metric for the vulnerability. The metric describes the impact on the integrity of the exploited system. Possible values include:\n - None\n - Partial\n - Complete"},"cwe":{"type":"string","description":"The Common Weakness Enumeration (CWE) ID for vulnerability."},"cpe":{"type":"array","description":"The systems the vulnerability affects identified by Common Platform Enumeration (CPE).","items":{"type":"string"}},"remediation":{"type":"string","description":"Remediation information for the vulnerability."},"references":{"type":"array","items":{"type":"string"},"description":"Additional references to third-party information about the vulnerability."}}},"package":{"type":"object","description":"A software packages affected by the vulnerability.","properties":{"name":{"type":"string","description":"The name of the package."},"version":{"type":"string","description":"The version of the package."},"type":{"type":"string","description":"The operating system or distribution associated with the package, for example, `linux`."}}},"installedPackage":{"type":"object","description":"A software package installed on the image.","properties":{"name":{"type":"string","description":"The name of the package."},"version":{"type":"string","description":"The version of the package."},"type":{"type":"string","description":"The operating system or distribution associated with the package, for example, `linux`."}}},"malware":{"type":"object","description":"The details of identified malware.","properties":{"infectedFile":{"type":"string","description":"The path of the infected file."},"fileTypeDescriptor":{"type":"string","description":"The file type of the infected file, for example, `ELF32`."},"md5":{"type":"string","description":"The MD5 signature of the infected file."},"sha256":{"type":"string","description":"The SHA256 signature of the infected file."}}},"unwantedProgram":{"description":"The unwanted program details.","type":"object","properties":{"infectedFile":{"type":"string","description":"The path of the program file."},"fileTypeDescriptor":{"type":"string","description":"The file type of the program file, for example, `ELF32`."},"md5":{"type":"string","description":"The MD5 signature of the program file."},"sha256":{"type":"string","description":"The SHA256 signature of the program file."}}},"pagination":{"type":"object","properties":{"total":{"type":"integer","description":"The total number of records matching your search criteria. Must be in the int32 format."},"limit":{"type":"integer","description":"Maximum number of records requested (or service imposed limit if not in request). Must be in the int32 format."},"offset":{"type":"integer","description":"The number of skipped records in the returned result set. Must be in the int32 format."},"sort":{"description":"An array of objects representing the fields you specified as sort parameters in the request. This attribute is only present if your request message specifies sort parameters.","type":"array","items":{"type":"object","properties":{"name":{"type":"string","description":"The name of the sort field."},"order":{"type":"string","description":"The direction in which Tenable.io sorts on the field, `asc` for ascending or `desc` for descending.","enum":["asc","desc"]}}}}}}}},"x-explorer-enabled":true,"x-proxy-enabled":true,"x-samples-enabled":true,"x-samples-languages":["python","curl","node","powershell","ruby","javascript","objectivec","java","php","csharp","go","swift","kotlin"]}