Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Azure Container Group resource is not configured to use a virtual network. This means containers are deployed without network isolation, exposing them directly to the public internet.

Impact#

Without a virtual network, containers are vulnerable to unauthorized network access, increasing the risk of attacks such as data exfiltration or service disruption. Attackers could exploit this to access sensitive resources or compromise workloads within your Azure environment.