Property
Languageterraform
Severitylow
CWECWE-326: Inadequate Encryption Strength
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Google Cloud Load Balancer is configured to allow outdated versions of TLS, rather than enforcing at least TLS 1.2. This weakens the security of encrypted connections to your services.

Impact#

Allowing insecure TLS versions exposes data in transit to interception or tampering by attackers, potentially leading to sensitive information leaks or man-in-the-middle attacks against users of your application.