Low

TitleLanguage
You should enable bucket access logging on the CloudTrail S3 bucket.terraform
Workloads in the default namespaceterraform
Web App uses the latest HTTP versionterraform
Web App has registration with AD enabledterraform
Web App accepts incoming client certificateterraform
Weak Password Requirementspython
VPC flow logs should be enabled for all subnetworksterraform
VM disks should be encrypted with Customer Supplied Encryption Keysterraform
Use of Weak Hashphp
Use of Unmaintained Third Party Componentshcl
Use of Potentially Dangerous Functionphp
Use of Obsolete Functionpython
Use of Insufficiently Random Valuesjava
Use of Insufficiently Random Valuesscala
Use of Inherently Dangerous Functiongo
Use of Incorrectly-Resolved Name or Referencepython
Use of Incorrectly-Resolved Name or Referencecsharp
Use of Hard-coded Cryptographic Keyregex
Use of Hard-coded Credentialspython
Use of Hard-coded Credentialsjavascript
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsgeneric
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Hard-coded Credentialsregex
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')java
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')go
Use of Externally-Controlled Format Stringpython
Use of Externally-Controlled Format Stringjavascript
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)swift
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)javascript
Use of a Broken or Risky Cryptographic Algorithmruby
Use of a Broken or Risky Cryptographic Algorithmpython
Use of a Broken or Risky Cryptographic Algorithmjava
Use of a Broken or Risky Cryptographic Algorithmjava
URL Redirection to Untrusted Site ('Open Redirect')python
URL Redirection to Untrusted Site ('Open Redirect')php
URL Redirection to Untrusted Site ('Open Redirect')php
URL Redirection to Untrusted Site ('Open Redirect')javascript
URL Redirection to Untrusted Site ('Open Redirect')javascript
URL Redirection to Untrusted Site ('Open Redirect')javascript
URL Redirection to Untrusted Site ('Open Redirect')typescript
Unprotected Transport of Credentialspython
Uncontrolled Search Path Elementjson
Uncontrolled Resource Consumptionjavascript
Uncontrolled Resource Consumptiongo
Unchecked Return Valuephp
The router has common private networkterraform
The required contact details should be set for security centerterraform
The nas instance has common private networkterraform
The instance has common private networkterraform
The elb has common private networkterraform
The db instance has common private networkterraform
Storage of Sensitive Data in a Mechanism without Access Controlrust
Stackdriver Monitoring should be enabledterraform
Stackdriver Logging should be enabledterraform
Server-Side Request Forgery (SSRF)python
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)javascript
Server-Side Request Forgery (SSRF)csharp
Server-Side Request Forgery (SSRF)csharp
Server-Side Request Forgery (SSRF)csharp
Server-Side Request Forgery (SSRF)csharp
Sensitive Cookie Without 'HttpOnly' Flagruby
Sensitive Cookie Without 'HttpOnly' Flagpython
Sensitive Cookie Without 'HttpOnly' Flagpython
Sensitive Cookie Without 'HttpOnly' Flagpython
Sensitive Cookie Without 'HttpOnly' Flagpython
Sensitive Cookie Without 'HttpOnly' Flagphp
Sensitive Cookie Without 'HttpOnly' Flagphp
Sensitive Cookie Without 'HttpOnly' Flagjava
Sensitive Cookie Without 'HttpOnly' Flagkotlin
Sensitive Cookie Without 'HttpOnly' Flaggo
Sensitive Cookie Without 'HttpOnly' Flaggo
Sensitive Cookie with Improper SameSite Attributepython
Sensitive Cookie with Improper SameSite Attributepython
Sensitive Cookie with Improper SameSite Attributepython
Sensitive Cookie with Improper SameSite Attributephp
Sensitive Cookie with Improper SameSite Attributego
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributepython
Sensitive Cookie in HTTPS Session Without 'Secure' Attributephp
Sensitive Cookie in HTTPS Session Without 'Secure' Attributejava
Sensitive Cookie in HTTPS Session Without 'Secure' Attributekotlin
Sensitive Cookie in HTTPS Session Without 'Secure' Attributego
Sensitive Cookie in HTTPS Session Without 'Secure' Attributego
Sensitive Cookie in HTTPS Session Without 'Secure' Attributegeneric
Sensitive Cookie in HTTPS Session Without 'Secure' Attributegeneric
Security threat alerts go to subcription owners and co-administratorsterraform
Secrets Manager should use customer managed keysterraform
SAM State machine must have X-Ray tracing enabledterraform
SAM State machine must have logging enabledterraform
SAM Function must have X-Ray tracing enabledterraform
SAM API must have X-Ray tracing enabledterraform
S3 buckets should each define an aws_s3_bucket_public_access_blockterraform
S3 Bucket Loggingterraform
Runtime/Default Seccomp profile not setterraform
Runtime/Default AppArmor profile not setterraform
Runs with UID <= 10000terraform
Runs with GID <= 10000terraform
Runs with a root primary or supplementary GIDterraform
RUN using 'wget' and 'curlterraform
Reusing a Nonce, Key Pair in Encryptionkotlin
Retention policy for flow logs should be enabled and set to greater than 90 daysterraform
resource quota usageterraform
Resource Management Errors (4.12)ocaml
Require Cmk Disabled Alarmterraform
Protection Mechanism Failureyaml
Permissive List of Allowed Inputstypescript
Permissive List of Allowed Inputstypescript
Permissive List of Allowed Inputsjava
Permissive Cross-domain Policy with Untrusted Domainshcl
Permissive Cross-domain Policy with Untrusted Domainshcl
Permissive Cross-domain Policy with Untrusted Domainshcl
Performance Insights encryption should use Customer Managed Keysterraform
Out-of-bounds Readcsharp
Origin Validation Errorphp
Origin Validation Errorphp
Origin Validation Errorcsharp
Omission of Security-relevant Informationhcl
Non-core volume types used.terraform
No user should have more than one active access key.terraform
No unauthorized access to API Gateway methodsterraform
No HEALTHCHECK definedterraform
MQ Broker should have general logging enabledterraform
Missing Support for Integrity Checkgeneric
Missing IAM Role to allow authorized users to manage incidents with AWS Support.terraform
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing Encryption of Sensitive Datahcl
Missing description for security group/security group rule.terraform
Missing description for security group/security group rule.terraform
Missing description for security group.terraform
Missing description for security group.terraform
Missing description for security group rule.terraform
Missing description for security group rule.terraform
Missing description for nas security group.terraform
Missing description for db security group.terraform
Misinterpretation of Inputgo
Memory requests not specifiedterraform
Memory not limitedterraform
Manages /etc/hoststerraform
Limit Root Account Usageterraform
limit range usageterraform
Lambda functions should have X-Ray tracing enabledterraform
Kubernetes should have 'Automatic upgrade' enabledterraform
Kubernetes should have 'Automatic repair' enabledterraform
Key Vault Secret should have an expiration date setterraform
Key vault Secret should have a content type setterraform
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorsterraform
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Management Errorshcl
Key Exchange without Entity Authenticationpython
Key Exchange without Entity Authenticationgo
Interpretation Conflictgo
Insufficiently Protected Credentialsruby
Insufficiently Protected Credentialsruby
Insufficiently Protected Credentialsruby
Insufficiently Protected Credentialspython
Insufficiently Protected Credentialspython
Insufficiently Protected Credentialsjavascript
Insufficiently Protected Credentialsjavascript
Insufficient Verification of Data Authenticityruby
Insufficient Verification of Data Authenticityjavascript
Insufficient Verification of Data Authenticityjavascript
Insufficient Verification of Data Authenticitygo
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Logginghcl
Insufficient Control of Network Message Volume (Network Amplification)yaml
Insertion of Sensitive Information into Log Filegeneric
Insertion of Sensitive Information into Log Filec
Insecure Temporary Filego
Insecure Storage of Sensitive Informationjavascript
Insecure Storage of Sensitive Informationjavascript
Information Loss or Omissionhcl
Inefficient Regular Expression Complexitypython
Incorrect Type Conversion or Castjava
Incorrect Type Conversion or Castkotlin
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourcehcl
Incorrect Permission Assignment for Critical Resourceyaml
Incorrect Default Permissionsruby
Incorrect Default Permissionsjava
Incorrect Comparisonphp
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')generic
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')hcl
Inclusion of Sensitive Information in Source Codeyaml
Inadequate Encryption Strengthpython
Inadequate Encryption Strengthjava
Inadequate Encryption Strengthkotlin
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthterraform
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Inadequate Encryption Strengthhcl
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributesruby
Improperly Controlled Modification of Dynamically-Determined Object Attributespython
Improperly Controlled Modification of Dynamically-Determined Object Attributespython
Improperly Controlled Modification of Dynamically-Determined Object Attributesphp
Improperly Controlled Modification of Dynamically-Determined Object Attributesjavascript
Improperly Controlled Modification of Dynamically-Determined Object Attributesjavascript
Improperly Controlled Modification of Dynamically-Determined Object Attributesjavascript
Improper Restriction of XML External Entity Referenceruby
Improper Restriction of XML External Entity Referencepython
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of XML External Entity Referencejavascript
Improper Restriction of Rendered UI Layers or Framesruby
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')python
Improper Privilege Managementjava
Improper Privilege Managementhcl
Improper Privilege Managementhcl
Improper Privilege Managementhcl
Improper Privilege Managementhcl
Improper Privilege Managementyaml
Improper Neutralization of Wildcards or Matching Symbolspython
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')python
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')python
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')javascript
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')scala
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ruby
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')python
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')typescript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')javascript
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')java
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')html
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')html
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')go
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')regex
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')generic
Improper Neutralization of Formula Elements in a CSV Filepython
Improper Neutralization of Escape, Meta, or Control Sequencesregex
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')bash
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')python
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')javascript
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')java
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')generic
Improper Management of Sensitive Trace Datageneric
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ruby
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')python
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')python
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')php
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')java
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')scala
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')go
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')generic
Improper Input Validationbash
Improper Input Validationpython
Improper Encoding or Escaping of Outputjavascript
Improper Encoding or Escaping of Outputjavascript
Improper Encoding or Escaping of Outputjavascript
Improper Encoding or Escaping of Outputgeneric
Improper Encoding or Escaping of Outputregex
Improper Encoding or Escaping of Outputregex
Improper Encoding or Escaping of Outputregex
Improper Control of Generation of Code ('Code Injection')ruby
Improper Control of Generation of Code ('Code Injection')php
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')javascript
Improper Control of Generation of Code ('Code Injection')java
Improper Control of Generation of Code ('Code Injection')java
Improper Control of Generation of Code ('Code Injection')java
Improper Control of Dynamically-Managed Code Resourcesgo
Improper Control of Dynamically-Managed Code Resourcesgo
Improper Control of Dynamically-Managed Code Resourcesyaml
Improper Certificate Validationpython
Improper Certificate Validationpython
Improper Certificate Validationjava
Improper Certificate Validationjava
Improper Certificate Validationcsharp
Improper Authorization in Handler for Custom URL Schemepython
Improper Authorizationphp
Improper Authorizationphp
Improper Authenticationphp
Improper Authenticationhcl
Improper Authenticationhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
Improper Access Controlhcl
IAM policies should not be granted directly to users.terraform
File Inclusionphp
External Control of File Name or Pathpython
External Control of File Name or Pathphp
Exposure of Sensitive Information to an Unauthorized Actorruby
Exposure of Sensitive Information to an Unauthorized Actorphp
Exposure of Sensitive Information to an Unauthorized Actorjava
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actorhcl
Exposure of Sensitive Information to an Unauthorized Actoryaml
Execution with Unnecessary Privilegeshcl
Execution with Unnecessary Privilegesyaml
Execution with Unnecessary Privilegesyaml
Execution with Unnecessary Privilegesyaml
Execution with Unnecessary Privilegesyaml
Ensure that the RotateKubeletServerCertificate argument is set to trueterraform
Ensure that the etcd data directory permissions are set to 700 or more restrictiveterraform
Ensure that the etcd data directory ownership is set to etcd:etcdterraform
Ensure that the admission control plugin ServiceAccount is setterraform
Ensure that the admission control plugin SecurityContextDeny is set if PodSecurityPolicy is not usedterraform
Ensure that the admission control plugin NodeRestriction is setterraform
Ensure that the admission control plugin NamespaceLifecycle is setterraform
Ensure that the admission control plugin EventRateLimit is setterraform
Ensure that the admission control plugin AlwaysPullImages is setterraform
Ensure that the admission control plugin AlwaysAdmit is not setterraform
Ensure that the --use-service-account-credentials argument is set to trueterraform
Ensure that the --token-auth-file parameter is not setterraform
Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriateterraform
Ensure that the --terminated-pod-gc-threshold argument is set as appropriateterraform
Ensure that the --service-account-private-key-file argument is set as appropriateterraform
Ensure that the --service-account-lookup argument is set to trueterraform
Ensure that the --service-account-key-file argument is set as appropriateterraform
Ensure that the --secure-port argument is not set to 0terraform
Ensure that the --root-ca-file argument is set as appropriateterraform
Ensure that the --profiling argument is set to falseterraform
Ensure that the --profiling argument is set to falseterraform
Ensure that the --profiling argument is set to falseterraform
Ensure that the --peer-client-cert-auth argument is set to trueterraform
Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriateterraform
Ensure that the --peer-auto-tls argument is not set to trueterraform
Ensure that the --kubelet-https argument is set to trueterraform
Ensure that the --kubelet-certificate-authority argument is set as appropriateterraform
Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriateterraform
Ensure that the --etcd-cafile argument is set as appropriateterraform
Ensure that the --encryption-provider-config argument is set as appropriateterraform
Ensure that the --DenyServiceExternalIPs is not setterraform
Ensure that the --client-cert-auth argument is set to trueterraform
Ensure that the --client-ca-file argument is set as appropriateterraform
Ensure that the --cert-file and --key-file arguments are set as appropriateterraform
Ensure that the --bind-address argument is set to 127.0.0.1terraform
Ensure that the --bind-address argument is set to 127.0.0.1terraform
Ensure that the --auto-tls argument is not set to trueterraform
Ensure that the --authorization-mode argument is not set to AlwaysAllowterraform
Ensure that the --authorization-mode argument includes RBACterraform
Ensure that the --authorization-mode argument includes Nodeterraform
Ensure that the --audit-log-path argument is setterraform
Ensure that the --audit-log-maxsize argument is set to 100 or as appropriateterraform
Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriateterraform
Ensure that the --audit-log-maxage argument is set to 30 or as appropriateterraform
Ensure that response caching is enabled for your Amazon API Gateway REST APIs.terraform
Ensure that Postgres errors are loggedterraform
Ensure that logging of long statements is disabled.terraform
Ensure Kubelet Client Certificate And Kubelet Client Key Are Setterraform
Ensure Container-Optimized OS (cos) is used for Kubernetes Engine Clusters Node imageterraform
Ensure a log metric filter and alarm exist for VPC changesterraform
Ensure a log metric filter and alarm exist for usage of root userterraform
Ensure a log metric filter and alarm exist for unauthorized API callsterraform
Ensure a log metric filter and alarm exist for security group changesterraform
Ensure a log metric filter and alarm exist for S3 bucket policy changesterraform
Ensure a log metric filter and alarm exist for route table changesterraform
Ensure a log metric filter and alarm exist for organisation changesterraform
Ensure a log metric filter and alarm exist for IAM policy changesterraform
Ensure a log metric filter and alarm exist for CloudTrail configuration changesterraform
Ensure a log metric filter and alarm exist for changes to network gatewaysterraform
Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL)terraform
Ensure a log metric filter and alarm exist for AWS Management Console sign-in without MFAterraform
Ensure a log metric filter and alarm exist for AWS Management Console authentication failuresterraform
Ensure a log metric filter and alarm exist for AWS Config configuration changesterraform
Enable the standard security center subscription tierterraform
Enable Performance Insights to detect potential problemsterraform
Enable Object Write Loggingterraform
Enable Object Read Loggingterraform
Enable IAM Access analyzer for IAM policies about all resources in each region.terraform
ECS clusters should have container insights enabledterraform
ECR Repository should use customer managed keys to allow more controlterraform
EBS volume encryption should use Customer Managed Keysterraform
DynamoDB tables should use at rest encryption with a Customer Managed Keyterraform
DocumentDB encryption should use Customer Managed Keysterraform
Do not allow users in a rolebinding to add other users to their rolebindingsterraform
Disks should be encrypted with customer managed encryption keysterraform
Disable Unused Credentials 45 Daysterraform
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Datapython
Deserialization of Untrusted Dataphp
Deserialization of Untrusted Datajavascript
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datajava
Deserialization of Untrusted Datacsharp
Delete expired TLS certificatesterraform
Delete expired SSL certificatesterraform
Default security group should restrict all trafficterraform
Default capabilities: some containers do not drop anyterraform
Default capabilities: some containers do not drop allterraform
Cryptographic Issuescsharp
Cross-Site Request Forgery (CSRF)ruby
Cross-Site Request Forgery (CSRF)ruby
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)python
Cross-Site Request Forgery (CSRF)php
Cross-Site Request Forgery (CSRF)php
Cross-Site Request Forgery (CSRF)javascript
Cross-Site Request Forgery (CSRF)java
Cross-Site Request Forgery (CSRF)java
Cross-Site Request Forgery (CSRF)go
Cross-Site Request Forgery (CSRF)generic
Cross-Site Request Forgery (CSRF)generic
Cross-Site Request Forgery (CSRF)csharp
Creating Debug Binarygeneric
CPU requests not specifiedterraform
CPU not limitedterraform
Containers must not set runAsUser to 0terraform
Container capabilities must only include NET_BIND_SERVICEterraform
Configurationgeneric
Configurationgeneric
Configurationgeneric
Configurationhcl
Compiler Removal of Code to Clear Buffersc
Command Shell in Externally Accessible Directorypython
Clusters should have IP aliasing enabledterraform
Clusters should be configured with Labelsterraform
CloudWatch log groups should be encrypted using CMKterraform
CloudTrail logs should be stored in S3 and also sent to CloudWatch Logsterraform
Cloud Storage buckets should be encrypted with a customer-managed key.terraform
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationpython
Cleartext Transmission of Sensitive Informationphp
Cleartext Transmission of Sensitive Informationphp
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjavascript
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationjava
Cleartext Transmission of Sensitive Informationkotlin
Cleartext Transmission of Sensitive Informationgeneric
Cleartext Transmission of Sensitive Informationregex
Cleartext Transmission of Sensitive Informationhcl
Buckets should have MFA deletion protection enabled.terraform
Authentication Bypass by Spoofinggeneric
API Gateway must have X-Ray tracing enabledterraform
ADD instead of COPYterraform
Active Debug Codepython
Active Debug Codepython
Active Debug Codepython
Active Debug Codepython
Active Debug Codephp
Active Debug Codego
Active Debug Coderegex
Active Debug Codegeneric
Active Debug Codeyaml
Access keys should be rotated at least every 90 daysterraform