Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Azure App Service is deployed without authentication enabled in its configuration. This means users can access the application without verifying their identity, leaving it unprotected.

Impact#

Without authentication, anyone can access your app, exposing sensitive data and functionality to unauthorized users. Attackers could exploit this to steal information, modify data, or disrupt your service, leading to data breaches and compliance violations.