cloudgoat icon indicating copy to clipboard operation
cloudgoat copied to clipboard

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Results 57 cloudgoat issues
Sort by recently updated
recently updated
newest added

Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.38.0 to 1.53.0. Release notes Sourced from google.golang.org/grpc's releases. Release 1.53.0 API Changes balancer: support injection of per-call metadata from LB policies (#5853) resolver: remove deprecated field...

dependencies
go

Replace aws_s3_bucket_object (deprecated) to aws_s3_object. Removing the ACL resource. Buckets by default are private.

In this PR I fixed some issues on various guides to standardize with the rest of the project. The changes include: - Applying bullets to "Scenario resources", so markdown shows...

Bumps [requests](https://github.com/psf/requests) from 2.26.0 to 2.31.0. Release notes Sourced from requests's releases. v2.31.0 2.31.0 (2023-05-22) Security Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential forwarding of Proxy-Authorization...

dependencies
python

## Error: while creating the iam_privesc_by_attachment scenario ``` │ Error: collecting instance settings: couldn't find resource │ │ with aws_instance.cg-super-critical-security-server, │ on ec2.tf line 56, in resource "aws_instance" "cg-super-critical-security-server": │...

#### Overview of Changes - Prevents the restoration of the RDS snapshot - [Discord issue](https://discord.com/channels/969671994599669760/1074135870753488906/1238144664331092122) #### Testing None

#### Overview of Changes For document unity, a dollar sign was added to indicate that it is a shell script.

#### Overview of Changes - Recommend using python virtual environments - Git ignore the `.venv` directory - Updated python packages to latest versions #### Testing Locally running scenarios (including ecs_takeover)...