Skip to content

Commit fa380ee

Browse files
authored
update CWEs for terraform rules (#3666)
1 parent f672cf3 commit fa380ee

File tree

108 files changed

+108
-108
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

108 files changed

+108
-108
lines changed

terraform/aws/security/aws-ec2-has-public-ip.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ rules:
3131
- A05:2017 - Broken Access Control
3232
- A01:2021 - Broken Access Control
3333
cwe:
34-
- 'CWE-284: Improper Access Control'
34+
- 'CWE-1220: Insufficient Granularity of Access Control'
3535
references:
3636
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
3737
subcategory:

terraform/aws/security/aws-ec2-security-group-allows-public-ingress.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ rules:
7373
owasp:
7474
- A01:2021 - Broken Access Control
7575
cwe:
76-
- 'CWE-284: Improper Access Control'
76+
- 'CWE-1220: Insufficient Granularity of Access Control'
7777
references:
7878
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
7979
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group

terraform/aws/security/aws-network-acl-allows-all-ports.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ rules:
4949
owasp:
5050
- A01:2021 - Broken Access Control
5151
cwe:
52-
- 'CWE-284: Improper Access Control'
52+
- 'CWE-1220: Insufficient Granularity of Access Control'
5353
references:
5454
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
5555
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/network_acl

terraform/aws/security/aws-network-acl-allows-public-ingress.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ rules:
7272
owasp:
7373
- A01:2021 - Broken Access Control
7474
cwe:
75-
- 'CWE-284: Improper Access Control'
75+
- 'CWE-1220: Insufficient Granularity of Access Control'
7676
references:
7777
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
7878
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/network_acl

terraform/aws/security/aws-redshift-cluster-encrypted-with-cmk.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ rules:
2323
- A05:2017 - Broken Access Control
2424
- A01:2021 - Broken Access Control
2525
cwe:
26-
- 'CWE-284: Improper Access Control'
26+
- 'CWE-1220: Insufficient Granularity of Access Control'
2727
references:
2828
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
2929
subcategory:

terraform/aws/security/aws-subnet-has-public-ip-address.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ rules:
3434
owasp:
3535
- A01:2021 - Broken Access Control
3636
cwe:
37-
- 'CWE-284: Improper Access Control'
37+
- 'CWE-1220: Insufficient Granularity of Access Control'
3838
references:
3939
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
4040
- https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/subnet#map_public_ip_on_launch

terraform/aws/security/aws-transfer-server-is-public.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ rules:
2424
- A05:2017 - Broken Access Control
2525
- A01:2021 - Broken Access Control
2626
cwe:
27-
- 'CWE-284: Improper Access Control'
27+
- 'CWE-1220: Insufficient Granularity of Access Control'
2828
references:
2929
- https://owasp.org/Top10/A01_2021-Broken_Access_Control
3030
subcategory:

terraform/aws/security/unrestricted-github-oidc-policy.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ rules:
1414
- A05:2017 - Sensitive Data Exposure
1515
- A01:2021 - Broken Access Control
1616
cwe:
17-
- "CWE-284: Improper Access Control"
17+
- "CWE-1220: Insufficient Granularity of Access Control"
1818
references:
1919
- https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-amazon-web-services#configuring-the-role-and-trust-policy
2020
- https://dagrz.com/writing/aws-security/hacking-github-aws-oidc/

terraform/azure/best-practice/azure-networkinterface-enable-ip-forwarding.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ rules:
1515
- A05:2017 - Broken Access Control
1616
- A01:2021 - Broken Access Control
1717
cwe:
18-
- 'CWE-284: Improper Access Control'
18+
- 'CWE-1220: Insufficient Granularity of Access Control'
1919
category: security
2020
technology:
2121
- terraform

terraform/azure/security/aks/azure-aks-apiserver-auth-ip-ranges.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ rules:
1919
- A05:2017 - Broken Access Control
2020
- A01:2021 - Broken Access Control
2121
cwe:
22-
- 'CWE-284: Improper Access Control'
22+
- 'CWE-1220: Insufficient Granularity of Access Control'
2323
category: security
2424
technology:
2525
- terraform

0 commit comments

Comments
 (0)