---
title: "Search Container Vulnerabilities"
method: POST
path: "/api/v2/Vulnerabilities/Containers/search"
tags: ["Vulnerabilities"]
---

# Search Container Vulnerabilities

`POST /api/v2/Vulnerabilities/Containers/search`

Search the scan (assessment), including the risk score and scan status, the vulnerabilities found in the scan, and statistics for those vulnerabilities by invoking the following endpoint:

  > `POST https://YourAccount.lacework.net/api/v2/Vulnerabilities/Containers/search` 

 FortiCNAPP highly recommends specifying a time range. Without a specified time range, the request uses the default time range of 24 hours prior to the current time. The maximum time range per API request is 7 days.  To use the current time as the end time, exclude the endTime field.

 You can optionally filter returned vulnerabilities by severity, vulnerability ID, machine ID, and more. For more information, see [CONTAINER_VULN_DETAILS_V View](https://docs.fortinet.com/document/forticnapp/latest/administration-guide/970831/container-vuln-details-v-view). 

 The `rlike` and `not_rlike` operators are useful for filtering results. For example, the following expression limits results to those that have `python` in their `featureKey` name field:

 > `"filters": [ {  "expression": "rlike", "field": "featureKey.name", "value": ".*python.*" } ]`   

 Here are additional example `body` payloads: 

 Here are some additional example `body` payloads: 
 * `{ "timeFilter": { "startTime": "2021-08-28T20:30:00Z", "endTime": "2021-08-28T22:30:00Z"},` 
 `"filters": [ { "field": "vulnId", "expression": "eq", "value": "CVE-2018-7169" } ] }` 
 * `{ "timeFilter": { "startTime": "2021-08-28T20:30:00Z", "endTime": "2021-08-28T22:30:00Z"},` 
 `"filters": [ { "field": "evalGuid", "expression": "eq", "value": "1234567a89012b34567890123cd56e78" } ] }` 
 * `{ "timeFilter": { "startTime": "2021-08-28T20:30:00Z", "endTime": "2021-08-28T22:30:00Z"},`
 `"filters": [ { "field": "evalCtx.image_info.digest", "expression": "eq", "value": "sha256:2e05f1f668367c1fc0f1c9c02ee87521ed66541e6ebf0a31905b8cdd78d22611" }, { "field": "severity", "expression": "eq", "value": "Medium" } ],`  
 `"returns": [ "imageId", "severity", "status", "vulnId", "evalCtx", "fixInfo", "featureKey" ] }`

To search for container vulnerabilities of only active containers, first use the "Search Containers" endpoint to get a list of active containers. Then call "Search Container Vulnerabilities" and pass the image IDs from the "Search Containers" results as a filter with the `in` filter type.

## Headers

- `Authorization` string, required
- `Content-Type` string, required

## Request body

- GETDATAREQUESTBODYTIMEFILTERS
  - `timeFilter` object — The date/time range during which actions occurred.
    - `startTime` string — Returns only recorded actions that occurred after this timestamp.
    - `endTime` string — Returns only recorded actions that occurred before this timestamp. If empty or missing, the current time is used.
  - `filters` object[] — One or more condition statements you can use to refine the data returned by the request. Only records that satisfy filtering conditions are returned. If there are multiple conditions, a record must satisfy all conditions for a match.
    - `expression` 'eq' | 'ne' | 'in' | 'not_in' | 'like' | 'ilike' | 'not_like' | 'not_ilike' | 'not_rlike' | 'rlike' | 'gt' | 'ge' | 'lt' | 'le' | 'between', required — The comparison operator for the filter condition.
    - `field` string, required — The name of the data field to which the condition applies.
    - `value` string — The value that the condition checks for in the specified field. Use this attribute when specifying a single value.
    - `values` string[] — The values that the condition checks for in the specified field. Use this attribute when specifying multiple values.
  - `returns` string[] — Use this attribute to specify which top-level fields of the response schema you want to receive.

## Response `200`

No Error (List of Container Vulnerabilities)

- object
  - `paging` PagingSchema — Details of the response's pagination
    - `rows` number — The number of rows displayed on each page
    - `totalRows` number — The number of rows returned from the query
    - `urls` object — Pagination-related URLs
      - `nextPage` string — The next page's URL
  - `data` VulnerabilitiesContainersResponseSchema[]
    - `startTime` string
    - `vulnId` string
    - `imageId` string
    - `evalCtx` object
    - `evalGuid` string
    - `featureKey` object
    - `featureProps` object
    - `packageStatus` string
    - `fixInfo` object
    - `severity` string
    - `status` string
    - `props` object
    - `riskScore` number
    - `riskInfo` object
    - `cveRiskScore` number
    - `cveRiskInfo` object
    - `imageRiskScore` number
    - `imageRiskInfo` object

## Other responses

- `204` — No Data
- `4XX` — Client Error
- `5XX` — Internal Server Error

---

[API](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation.md) · [All operations](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/lacework/forticnapp-api-2-0-documentation/versions/7015f76895f2/schema)
