Property
Languagehcl
Severitylow
CWECWE-320: CWE CATEGORY: Key Management Errors
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The PostgreSQL server resource in your Terraform configuration does not have infrastructure encryption enabled. This means data stored on Azure’s infrastructure is not encrypted at rest, increasing the risk of unauthorized data access.

Impact#

Without infrastructure encryption, sensitive data could be exposed if Azure’s underlying storage is compromised or accessed by unauthorized parties. This can lead to data breaches, regulatory non-compliance, and loss of trust in your application or organization.