AVD-AZU-0051 triggers on any public IP, not just /0 #7135
Closed
chanster
started this conversation in
False Detection
Replies: 1 comment 1 reply
-
We should update the title in this case. The |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
AVD-AZU-0051
Description
The title of the check is An outbound network security rule allows traffic to /0 but the actual trigger is any public IP range.
The code is just checking if the IP is a public IP and does not validate the mask. The title or triggger should be updated to match the other.
Link to specific code line: https://github.com/aquasecurity/trivy-checks/blame/3c54ac8393e3ae60e70a638940f5dbb636717843/checks/cloud/azure/network/no_public_egress.go#L43)
Reproduction Steps
Target
Filesystem
Scanner
Misconfiguration
Target OS
n/a
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions