Property
Languagehcl
Severitymedium
CWECWE-262: Not Using Password Aging
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelLow

Description#

Keys in Azure Key Vault are being created without an expiration date. This means the keys will remain valid indefinitely unless manually deleted or rotated.

Impact#

If keys do not expire, compromised or outdated keys could be misused for extended periods, increasing the risk of unauthorized access or data breaches. This weakens key lifecycle management and can result in non-compliance with security policies.