PulseAugur
实时 09:45:09
English(EN) Vulnerabilities, Secrets and Misconfiguration in the Highest-Exposure Docker Hub Images

研究发现 Docker Hub 镜像普遍存在漏洞

一项对超过 1200 万个 Docker Hub 仓库的分析新研究揭示了普遍存在的漏洞和错误配置。研究发现,96.3% 的镜像包含已知的软件包漏洞,其中 93.4% 存在严重漏洞,98.0% 存在至少一项 CIS Docker Benchmark 错误配置。研究还强调了不同扫描工具之间存在显著差异,许多发现仅对单一扫描器有效,并且秘密检测的误报率很高。尽管漏洞普遍存在,但研究指出镜像的暴露程度与其漏洞状态不相关。 AI

影响 凸显了许多 AI 部署和 MLOps 管道基础架构中的关键安全风险。

排序理由 学术论文,详细介绍了 Docker Hub 镜像的新扫描管道和数据集。[lever_c_demoted from research: ic=1 ai=0.7]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

研究发现 Docker Hub 镜像普遍存在漏洞

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Cristhian Kapelinski, Beatriz Machado, Diego Kreutz ·

    Docker Hub 暴露率最高镜像中的漏洞、秘密和错误配置

    arXiv:2608.02669v1 Announce Type: cross Abstract: Docker Hub is the registry underneath most container deployments, and a flaw in a widely reused base image is inherited by every image built on it. Prior ecosystem-scale measurements each rely on a single detector, leaving the too…