Property
Languagehcl
Severitymedium
CWECWE-732: Incorrect Permission Assignment for Critical Resource
OWASPA05:2021 - Security Misconfiguration
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelMedium

Description#

The ECR repository policy is granting access to all users by using a wildcard (’*’) as the principal. This makes the repository publicly accessible, exposing images to anyone on the internet.

Impact#

If exploited, unauthorized users could pull, push, or delete container images in your repository. This could lead to data leaks, service disruptions, or compromise of your application supply chain.