nebari-dev / governance

āœØ Governance-related work for Nebari-dev
BSD 3-Clause "New" or "Revised" License
0 stars 2 forks source link

RFD - GitLab SAST scans report critical & high vulnerabilities for Nebari in AWS #55

Open joneszc opened 2 months ago

joneszc commented 2 months ago
Status Draft šŸš§ / Open for comments šŸ’¬
Author(s) @joneszc
Date Created 05-09-2024
Date Last updated dd-MM-YYY
Decision deadline N/A

Title

SAST Scans Show Nebari Has Critical/High Vulnerabilities in AWS

Summary

Of the several critical vulnerabilities reported by GitLab SAST for Nebari, deployed in AWS, some vulnerabilities could be mitigated by adding AWS Key Management Service (KMS) controls & configuration options in addition to applying encryption as default settings in the corresponding AWS services:

User benefit

Defense in Depth Security Strategy

Design Proposal

MITIGATION:

Alternatives or approaches considered (if any)

Best practices

User impact

Unresolved questions