Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(internet-exposed): Improve publicly accessible checks to include targets of ELBs #3920

Closed
wants to merge 11 commits into from

Conversation

abant07
Copy link

@abant07 abant07 commented May 3, 2024

Context

Currently, we are checking if resources are internet facing and then flagging it as a failed test to the user, however, there is possibility that the user has configured security groups for their resources but have forgotten to configure for their load balancers. This can potentially be a security threat as anyone from the internet can access their load balancer and have the ability to hack their resources.

Description

No dependencies have been added, however, I have added 2 checks for EC2, 1 check for Lambda, and 1 check for ECS to make sure that ELBs and ELBv2s are either internal or if they are internet facing they should have security groups.

License

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@abant07 abant07 requested review from a team as code owners May 3, 2024 18:25
@github-actions github-actions bot added the provider/aws Issues/PRs related with the AWS provider label May 3, 2024
@jfagoagas jfagoagas added the no-merge Please, DO NOT MERGE this PR. label May 6, 2024
@abant07 abant07 closed this May 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
no-merge Please, DO NOT MERGE this PR. provider/aws Issues/PRs related with the AWS provider
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants