Skip to content

Comments

Update cfngoat.yaml#15

Open
ankit1128 wants to merge 1 commit intomasterfrom
ankit1128-patch-14
Open

Update cfngoat.yaml#15
ankit1128 wants to merge 1 commit intomasterfrom
ankit1128-patch-14

Conversation

@ankit1128
Copy link
Owner

No description provided.

Copy link

@prisma-cloud-devsecops prisma-cloud-devsecops bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prisma Cloud has found errors in this PR ⬇️

SubnetId: !Ref WebSubnet
Tags:
- Key: Name
- Key: Name1

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HIGH  EC2 user data exposes secrets
    Resource: AWS | Bridgecrew ID: BC_AWS_SECRETS_1 | Checkov ID: CKV_AWS_46

Description

**User Data** is a metadata field of an EC2 instance that allows custom code to run after the instance is launched. It contains code exposed to any entity which has the most basic access to EC2, even read-only configurations. This code is not encrypted.

Removing secrets from easily-accessed unencrypted places reduces the risk of passwords, private keys and more from being exposed to third parties.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant