Threagile / threagile

Agile Threat Modeling Toolkit
https://threagile.io
MIT License
577 stars 126 forks source link

Risk - Public Access on Cloud Assets #26

Open BenjiTrapp opened 2 years ago

BenjiTrapp commented 2 years ago

Risk: Public exposure and/or access of cloud based assets like S3/S3 ACLs/SQS due to a misconfigured Policy that is containing Wildcards leading to data leakage or temparing of data and/or services

Remidiation: Audit of the Policies, reducing rights to a bare minimum, label assets as public and make sure the assets are isolated