False negative when SecurityGroupIngress is defined at resource level #6752
Closed
danfaizer
started this conversation in
False Detection
Replies: 2 comments
-
@nikpivkin can you take a look? |
Beta Was this translation helpful? Give feedback.
0 replies
-
Hi @danfaizer ! I created issue #6754 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
AVD-AWS-0107
Description
You can define a SecurityGroupIngress in 2 ways:
In case 1. the security control works and the "too broad" access is reported.
In case 2. the security control does not work and the "too broad" access is NOT reported.
The control should be reported in both definitions.
Reproduction Steps
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions