checkov icon indicating copy to clipboard operation
checkov copied to clipboard

False Positive check with json plan file CKV2_AWS_11

Open NevoWeksler opened this issue 2 years ago • 2 comments

Describe the issue Check Id: CKV2_AWS_11 There is a false positive (the check is failing when in reality the VPC flow logs are enabled) the main.tf file refers to aws_vpc module. the code attached is of the json plan file. changed to txt to upload the file because json is not supported here.

Examples plan_file.txt

Version (please complete the following information):

  • Checkov Version 2.2.30

Additional context also tested on my local machine using the command: checkov -f ./plan_file.json -c CKV2_AWS_11 --quiet the outcome: image

NevoWeksler avatar Nov 14 '22 09:11 NevoWeksler

hey @NevoWeksler thanks for reaching out. This is well-known bug and happens, if you use the same module twice. The connection mapping gets messed up and all the similar connections are targeting just one resource, that's why you see one error, even deploying 2 VPCs with flow logs enabled.

gruebel avatar Nov 14 '22 09:11 gruebel

H, @gruebel thanks for the quick reply, do you have a workaround by any chance? as i am blocking deployment of TF in my env because of those types of things.

NevoWeksler avatar Nov 14 '22 10:11 NevoWeksler

Have the same issue , but what I noticed, that I have this error only when I specify log destination.

dzirg44 avatar Feb 12 '23 13:02 dzirg44

Thanks for contributing to Checkov! We've automatically marked this issue as stale to keep our issues list tidy, because it has not had any activity for 6 months. It will be closed in 14 days if no further activity occurs. Commenting on this issue will remove the stale tag. If you want to talk through the issue or help us understand the priority and context, feel free to add a comment or join us in the Checkov slack channel at https://slack.bridgecrew.io Thanks!

stale[bot] avatar Aug 11 '23 15:08 stale[bot]

Closing issue due to inactivity. If you feel this is in error, please re-open, or reach out to the community via slack: https://slack.bridgecrew.io Thanks!

stale[bot] avatar Sep 05 '23 00:09 stale[bot]