{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T01:00:42Z","timestamp":1784595642886,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,3,22]],"date-time":"2017-03-22T00:00:00Z","timestamp":1490140800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","award":["H98230-14-C-0139"],"award-info":[{"award-number":["H98230-14-C-0139"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,3,22]]},"DOI":"10.1145\/3029806.3029832","type":"proceedings-article","created":{"date-parts":[[2017,3,20]],"date-time":"2017-03-20T12:34:59Z","timestamp":1490013299000},"page":"269-280","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":148,"title":["A Study of Security Vulnerabilities on Docker Hub"],"prefix":"10.1145","author":[{"given":"Rui","family":"Shu","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaohui","family":"Gu","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Enck","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2017,3,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Browse vulnerabilities by date from CVE Details. http:\/\/www.cvedetails.com\/browse-by-date.php\/.  Browse vulnerabilities by date from CVE Details. http:\/\/www.cvedetails.com\/browse-by-date.php\/."},{"key":"e_1_3_2_1_2_1","unstructured":"CVE-2015--1781. http:\/\/www.cvedetails.com\/cve\/CVE-2015--1781\/.  CVE-2015--1781. http:\/\/www.cvedetails.com\/cve\/CVE-2015--1781\/."},{"key":"e_1_3_2_1_3_1","unstructured":"CVE-2015--4000. http:\/\/www.cvedetails.com\/cve\/CVE-2015--4000\/.  CVE-2015--4000. http:\/\/www.cvedetails.com\/cve\/CVE-2015--4000\/."},{"key":"e_1_3_2_1_4_1","unstructured":"CVE\n  : Common Vulnerabilities and Exposures. https:\/\/cve.mitre.org\/.  CVE: Common Vulnerabilities and Exposures. https:\/\/cve.mitre.org\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Docker Bench for Security. https:\/\/github.com\/docker\/docker-bench-security.  Docker Bench for Security. https:\/\/github.com\/docker\/docker-bench-security."},{"key":"e_1_3_2_1_6_1","unstructured":"National Vulnerability Database. https:\/\/nvd.nist.gov\/home.cfm.  National Vulnerability Database. https:\/\/nvd.nist.gov\/home.cfm."},{"key":"e_1_3_2_1_7_1","unstructured":"NCSU Virtual Computing Lab. https:\/\/vcl.ncsu.edu\/.  NCSU Virtual Computing Lab. https:\/\/vcl.ncsu.edu\/."},{"key":"e_1_3_2_1_8_1","unstructured":"NVD Common Vulnerability Scoring System. https:\/\/nvd.nist.gov\/cvss.cfm.  NVD Common Vulnerability Scoring System. https:\/\/nvd.nist.gov\/cvss.cfm."},{"key":"e_1_3_2_1_9_1","unstructured":"Repositories on Docker Hub. https:\/\/docs.docker.com\/docker-hub\/repos\/.  Repositories on Docker Hub. https:\/\/docs.docker.com\/docker-hub\/repos\/."},{"key":"e_1_3_2_1_10_1","unstructured":"RHSA to CVE and CPE mapping. https:\/\/www.redhat.com\/security\/data\/metrics\/rhsamapcpe.txt.  RHSA to CVE and CPE mapping. https:\/\/www.redhat.com\/security\/data\/metrics\/rhsamapcpe.txt."},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of APSEC 2010 Cloud Workshop","author":"Almorsy M.","year":"2010","unstructured":"M. Almorsy , J. Grundy , I. M\u00fcller , An analysis of the cloud computing security problem . In Proceedings of APSEC 2010 Cloud Workshop , Sydney, Australia, 30th Nov , 2010 . M. Almorsy, J. Grundy, I. M\u00fcller, et al. An analysis of the cloud computing security problem. In Proceedings of APSEC 2010 Cloud Workshop, Sydney, Australia, 30th Nov, 2010."},{"key":"e_1_3_2_1_12_1","unstructured":"Banyan Collector. https:\/\/github.com\/banyanops\/collector.  Banyan Collector. https:\/\/github.com\/banyanops\/collector."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.70725"},{"key":"e_1_3_2_1_14_1","volume-title":"Vulnerability exploitation in Docker container environments. https:\/\/www.blackhat.com\/docs\/eu-15\/materials\/eu-15-Bettini-Vulnerability-Exploitation-In-Docker-Container-Environments-wp.pdf","author":"Bettini A.","year":"2015","unstructured":"A. Bettini . Vulnerability exploitation in Docker container environments. https:\/\/www.blackhat.com\/docs\/eu-15\/materials\/eu-15-Bettini-Vulnerability-Exploitation-In-Docker-Container-Environments-wp.pdf , 2015 . A. Bettini. Vulnerability exploitation in Docker container environments. https:\/\/www.blackhat.com\/docs\/eu-15\/materials\/eu-15-Bettini-Vulnerability-Exploitation-In-Docker-Container-Environments-wp.pdf, 2015."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046753"},{"key":"e_1_3_2_1_16_1","unstructured":"CoreOS Clair. https:\/\/github.com\/coreos\/clair.  CoreOS Clair. https:\/\/github.com\/coreos\/clair."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421004"},{"key":"e_1_3_2_1_18_1","unstructured":"Debian Security Bug Tracker. https:\/\/security-tracker.debian.org\/tracker.  Debian Security Bug Tracker. https:\/\/security-tracker.debian.org\/tracker."},{"key":"e_1_3_2_1_19_1","volume-title":"August","author":"DeHamer B.","year":"2015","unstructured":"B. DeHamer . Docker Hub Top 10. https:\/\/www.ctl.io\/developers\/blog\/post\/docker-hub-top-10\/ , August 2015 . B. DeHamer. Docker Hub Top 10. https:\/\/www.ctl.io\/developers\/blog\/post\/docker-hub-top-10\/, August 2015."},{"key":"e_1_3_2_1_20_1","unstructured":"Docker Security Scanning. https:\/\/docs.docker.com\/docker-cloud\/builds\/image-scan\/.  Docker Security Scanning. https:\/\/docs.docker.com\/docker-cloud\/builds\/image-scan\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-013-0208-7"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1932682.1869475"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.115"},{"key":"e_1_3_2_1_24_1","volume-title":"BanyanOps","author":"Gummaraju J.","year":"2015","unstructured":"J. Gummaraju , T. Desikan , and Y. Turner . Over 30% of official images in docker hub contain high priority security vulnerabilities. Technical report , BanyanOps , 2015 . J. Gummaraju, T. Desikan, and Y. Turner. Over 30% of official images in docker hub contain high priority security vulnerabilities. Technical report, BanyanOps, 2015."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1186\/1869-0238-4-5"},{"key":"e_1_3_2_1_26_1","first-page":"36","volume-title":"Three misuse patterns for cloud computing. Security engineering for Cloud Computing: approaches and Tools","author":"Hashizume K.","year":"2012","unstructured":"K. Hashizume , N. Yoshioka , and E. B. Fernandez . Three misuse patterns for cloud computing. Security engineering for Cloud Computing: approaches and Tools , pages 36 -- 53 , 2012 . K. Hashizume, N. Yoshioka, and E. B. Fernandez. Three misuse patterns for cloud computing. Security engineering for Cloud Computing: approaches and Tools, pages 36--53, 2012."},{"key":"e_1_3_2_1_27_1","unstructured":"IBM's Vulnerability Advisor. http:\/\/www-03.ibm.com\/press\/us\/en\/pressrelease\/47165.wss.  IBM's Vulnerability Advisor. http:\/\/www-03.ibm.com\/press\/us\/en\/pressrelease\/47165.wss."},{"key":"e_1_3_2_1_28_1","unstructured":"Is FROM scratch the root of all Docker Images? https:\/\/www.ctl.io\/developers\/blog\/post\/is-from-scratch-the-root-of-all-docker-images\/.  Is FROM scratch the root of all Docker Images? https:\/\/www.ctl.io\/developers\/blog\/post\/is-from-scratch-the-root-of-all-docker-images\/."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.13"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.30"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2002.1019480"},{"key":"e_1_3_2_1_32_1","unstructured":"Library of official images. https:\/\/github.com\/docker-library\/official-images\/tree\/master\/library\/.  Library of official images. https:\/\/github.com\/docker-library\/official-images\/tree\/master\/library\/."},{"key":"e_1_3_2_1_33_1","unstructured":"OpenSCAP Container Compliance. https:\/\/github.com\/OpenSCAP\/container-compliance.  OpenSCAP Container Compliance. https:\/\/github.com\/OpenSCAP\/container-compliance."},{"key":"e_1_3_2_1_34_1","unstructured":"Red Hat Security Data. https:\/\/www.redhat.com\/security\/data\/metrics\/.  Red Hat Security Data. https:\/\/www.redhat.com\/security\/data\/metrics\/."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1346256.1346272"},{"key":"e_1_3_2_1_36_1","unstructured":"Twistlock. https:\/\/www.twistlock.com\/product\/vulnerabilitymanagement\/.  Twistlock. https:\/\/www.twistlock.com\/product\/vulnerabilitymanagement\/."},{"key":"e_1_3_2_1_37_1","unstructured":"Ubuntu CVE Tracker. https:\/\/launchpad.net\/ubuntu-cve-tracker.  Ubuntu CVE Tracker. https:\/\/launchpad.net\/ubuntu-cve-tracker."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591971.2592003"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655008.1655021"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590300"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920317"}],"event":{"name":"CODASPY '17: Seventh ACM Conference on Data and Application Security and Privacy","location":"Scottsdale Arizona USA","acronym":"CODASPY '17","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3029806.3029832","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3029806.3029832","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:50:29Z","timestamp":1750218629000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3029806.3029832"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,3,22]]},"references-count":41,"alternative-id":["10.1145\/3029806.3029832","10.1145\/3029806"],"URL":"https:\/\/doi.org\/10.1145\/3029806.3029832","relation":{},"subject":[],"published":{"date-parts":[[2017,3,22]]},"assertion":[{"value":"2017-03-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}