Property
Languagetypescript
Severitymedium
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelMedium

Description#

The S3 bucket is created without enforcing SSL connections (’enforceSSL’ is not set to true), allowing clients to access the bucket over unencrypted HTTP. This exposes any data transmitted to or from the bucket to interception.

Impact#

Sensitive information stored or retrieved from the S3 bucket could be intercepted by attackers if accessed over insecure connections. This may lead to data leaks, compliance violations, and increases the risk of man-in-the-middle attacks compromising your application’s confidentiality.