Domain name for API request: cwp.intl.tencentcloudapi.com.
Application defense event details
A maximum of 20 requests can be initiated per second for this API.
The following request parameter list only provides API request parameters and some common parameters. For the complete common parameter list, see Common Request Parameters.
| Parameter Name | Required | Type | Description |
|---|---|---|---|
| Action | Yes | String | Common Params. The value used for this API: DescribeRaspEventDetailTCSS. |
| Version | Yes | String | Common Params. The value used for this API: 2018-02-28. |
| Region | No | String | Common Params. This parameter is not required. |
| Id | No | Integer | Vulnerability Event ID |
| Parameter Name | Type | Description |
|---|---|---|
| Data | RaspEventDetail | Application protection event details |
| RequestId | String | The unique request ID, generated by the server, will be returned for every request (if the request fails to reach the server for other reasons, the request will not obtain a RequestId). RequestId is required for locating a problem. |
Retrieve container vulnerability defense or memory shell injection alert details
POST / HTTP/1.1
Host: cwp.intl.tencentcloudapi.com
Content-Type: application/json
X-TC-Action: DescribeRaspEventDetailTCSS
<Common request parameters>
{
"Id": 10010
}
{
"Response": {
"Data": {
"Alias": "",
"AttackPort": 0,
"AttackType": 0,
"AttackTypeName": "",
"City": "Guangdong Province-Shenzhen",
"ClusterId": "",
"ClusterName": "",
"ContainerId": "645fa43394287c5fa81095a6ac29ce0382caadc6c2b541d7580fc14af0539c33",
"ContainerName": "/gracious_saha",
"ContainerNetStatus": "",
"ContainerStatus": "",
"Count": 3,
"CreateTime": "2022-07-25 16:20:49",
"CveId": "CVE-2021-44832",
"Description": "Apache Log4j2 issued a security bulletin. Versions prior to 2.17.1 are vulnerable to remote code execution attacks. When the attacker is authorized to modify the log configuration, remote code execution can occur."
"Fix": "Please note that this vulnerability only detects versions of log4j-core files. In the default configuration, detection will still occur.\n\nOnly log4j-core JAR files are affected by this vulnerability. Applications that use only log4j-api JAR files without log4j-core JAR files are not impacted. Tencent security expert recommends affected users upgrade to version 2.17.1 and above versions as soon as possible.\nFor the latest secure version, refer to the official security bulletin: https://logging.apache.org/log4j/2.x/security.html\nUpdate package download link: https://logging.apache.org/log4j/2.x/download.html"
"HostTags": [],
"Id": 0,
"ImageId": "sha256:d76d5658637ff855abdfda4d66eaa4c8f765eb9299456d984c8050e0974208f2",
"ImageName": "tomcat7:jdk8",
"InstanceID": "",
"MainClass": "org.apache.catalina.startup.Bootstrap",
"MergeTime": "2022-07-25 16:27:53",
"NetworkPayload": "aG9zdDoxMDYuNTIuMjkuMTMzOjg4ODgKY29ubmVjdGlvbjprZWVwLWFsaXZlCmNvbnRlbnQtbGVuZ3RoOjcwCmNhY2hlLWNvbnRyb2w6bWF4LWFnZT0wCnVwZ3JhZGUtaW5zZWN1cmUtcmVxdWVzdHM6MQpvcmlnaW46aHR0cDovLzEwNi41Mi4yOS4xMzM6ODg4OApjb250ZW50LXR5cGU6YXBwbGljYXRpb24veC13d3ctZm9ybS11cmxlbmNvZGVkCnVzZXItYWdlbnQ6TW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzEwMy4wLjAuMCBTYWZhcmkvNTM3LjM2CmFjY2VwdDp0ZXh0L2h0bWwsYXBwbGljYXRpb24veGh0bWwreG1sLGFwcGxpY2F0aW9uL3htbDtxPTAuOSxpbWFnZS9hdmlmLGltYWdlL3dlYnAsaW1hZ2UvYXBuZywqLyo7cT0wLjgsYXBwbGljYXRpb24vc2lnbmVkLWV4Y2hhbmdlO3Y9YjM7cT0wLjkKcmVmZXJlcjpodHRwOi8vMTA2LjUyLjI5LjEzMzo4ODg4L2xvZzRqLwphY2NlcHQtZW5jb2Rpbmc6Z3ppcCwgZGVmbGF0ZQphY2NlcHQtbGFuZ3VhZ2U6emgtQ04semg7cT0wLjksZW47cT0wLjgKY29va2llOkpTRVNTSU9OSUQ9N0Y5OTc4NkVENDc3RUU4MTEwODlBOEVCMTMwQjExRkY7IEpTRVNTSU9OSUQ9NDkzQUY0QzE4QjYxOTQ0NTEzNDMyOEEwMEVFREQ5RjYK",
"NodeId": "",
"NodeName": "",
"Pid": 240223,
"PodIp": "",
"PodName": "",
"PrivateIp": "",
"PublicIp": "",
"Quuid": "05f0bcab-726c-4ea4-8109-bcd03d5598f7",
"RaspDetail": "[{\"name\":\"jndiurl\",\"value\":\"ldap://m1111cak1z.dnslog.cn/\"}]",
"SourceIp": "113.108.77.67",
"StackTrace": "org.apache.logging.log4j.core.net.JndiManager.lookup\norg.apache.logging.log4j.core.lookup.JndiLookup.lookup\norg.apache.logging.log4j.core.lookup.Interpolator.lookup\norg.apache.logging.log4j.core.lookup.StrSubstitutor.resolveVariable\norg.apache.logging.log4j.core.lookup.StrSubstitutor.substitute\norg.apache.logging.log4j.core.lookup.StrSubstitutor.substitute\norg.apache.logging.log4j.core.lookup.StrSubstitutor.replace\norg.apache.logging.log4j.core.pattern.MessagePatternConverter.format\norg.apache.logging.log4j.core.pattern.PatternFormatter.format\norg.apache.logging.log4j.core.layout.PatternLayout.toSerializable\norg.apache.logging.log4j.core.layout.PatternLayout.toSerializable\norg.apache.logging.log4j.core.layout.AbstractStringLayout.toByteArray\norg.apache.logging.log4j.core.appender.AbstractOutputStreamAppender.append\norg.apache.logging.log4j.core.config.AppenderControl.callAppender\norg.apache.logging.log4j.core.config.LoggerConfig.callAppenders\norg.apache.logging.log4j.core.config.LoggerConfig.log\norg.apache.logging.log4j.core.config.LoggerConfig.log\norg.apache.logging.log4j.core.Logger.logMessage\norg.apache.logging.log4j.spi.AbstractLogger.logMessage\norg.apache.logging.log4j.spi.AbstractLogger.logIfEnabled\norg.apache.logging.log4j.spi.AbstractLogger.error\ncom.ki.demo2.BaseServlet.doPost\njavax.servlet.http.HttpServlet.service\njavax.servlet.http.HttpServlet.service\norg.apache.catalina.core.ApplicationFilterChain.internalDoFilter\norg.apache.catalina.core.ApplicationFilterChain.doFilter\norg.apache.catalina.core.StandardWrapperValve.invoke\norg.apache.catalina.core.StandardContextValve.invoke\norg.apache.catalina.authenticator.AuthenticatorBase.invoke\norg.apache.catalina.core.StandardHostValve.invoke\norg.apache.catalina.valves.ErrorReportValve.invoke\norg.apache.catalina.valves.AccessLogValve.invoke\norg.apache.catalina.core.StandardEngineValve.invoke\norg.apache.catalina.connector.CoyoteAdapter.service\norg.apache.coyote.http11.AbstractHttp11Processor.process\norg.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process\norg.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run\njava.util.concurrent.ThreadPoolExecutor.runWorker\njava.util.concurrent.ThreadPoolExecutor$Worker.run\njava.lang.Thread.run\n",
"Status": 0,
"Url": "",
"VulName": "Apache log4j2 remote code execution vulnerability (CVE-2021-44832)"
},
"RequestId": "b38481d0-106b-49d8-8069-19be9a2f4425"
}
}
TencentCloud API 3.0 integrates SDKs that support various programming languages to make it easier for you to call APIs.
There is no error code related to the API business logic. For other error codes, please see Common Error Codes.
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback