Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Azure Cache for Redis resource is configured with public network access enabled, allowing anyone on the internet to reach the cache instance. This exposes sensitive data and services to unauthorized users.

Impact#

If public network access is not disabled, attackers could connect to the Redis cache from outside the organization, potentially leading to data leaks, tampering, or disruption of application services. This increases the risk of unauthorized access and breaches.