kics
kics copied to clipboard
fix(queries): align queries cross different platforms
align queries cross different platforms
References: https://github.com/Checkmarx/kics/pull/5460 https://github.com/Checkmarx/kics/pull/5446
Proposed Changes align queries cross different platforms
Queries:
- API Gateway without WAF
- CloudTrail Log File Validation Disabled
- CloudTrail Log Files Not Encrypted With CMK
- DB Instance Publicly Accessible
- Hardcoded AWS Access Key In Lambda
- IAM Password Without Number
- S3 Bucket Logging Disabled
- SQL Analysis Services Port 2383 (TCP) Is Publicly Accessible
- Stack Notifications Disabled
- Azure Container Registry With No Locks
- Public Storage Account
- Redis Cache Allows Non SSL Connections
- COS Node Image Not Used
- Google Compute Subnetwork with Private Google Access Disabled
- High Google KMS Crypto Key Rotation Period
- High KMS Rotation Period
- Serial Ports Are Enabled For VM Instances
- SSH Access Is Not Restricted
- Using Default Service Account
- Cloudfront Logging Disabled
- Cloudfront Without WAF
- CodeBuild Not Encrypted
- DB Security Group With Public Scope
- ECS Service Admin Role is Present
- User Data Contains Encoded Private Key
- Authentication Without MFA
- CA Certificate Identifier Is Outdated
- ElasticSearch Without Slow Logs
- Hardcoded AWS Access Key
- SQS with SSE disabled
- AKS Network Policy Misconfigured
- CosmosDB Account IP Range Filter Not Set
- Role Definition Allows Custom Role Creation
- Unrestricted SQL Server Access
I submit this contribution under the Apache-2.0 license.
@rjegoncalves can you please review the changes?
@rafaela-soares any update on this?
@rafaela-soares any update on this?
Hello, @roi-orca! The PR is already being reviewed. Sorry for the delay. We will update you, as soon as possible 😊
Hi @rafaela-soares,
Regarding the comments of This description could have more details about the impact
Do you mean how actually the issue should be resolved in the platform?
Hi @rafaela-soares, Regarding the comments of
This description could have more details about the impact
Do you mean how actually the issue should be resolved in the platform?
Hi, @roi-orca! We mean how the vulnerability can impact the environment or the user. For example, regarding the query DB Instance Publicly Accessible
, the fact that the db is public will make the attack surface bigger and more susceptible to attacks.
Hello, @roi-orca! Feel free to ping me if you need something from our side in order to close this PR! ⛵ If you prefer, we can close it in our side.