forked from DefenderForCodeOrg/astlab
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
Checkmarx (IaC-Security): ALB Not Dropping Invalid Headers
Checkmarx Project: hirendgithub/astlab-fork
Repository URL: https://github.com/hirendgithub/astlab-fork
Branch: main
Scan ID: 3b325f77-d5e9-4a6d-8654-67201e0073df
It's considered a best practice when using Application Load Balancers to drop invalid header fields
Locations:
Result 1:
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
File: /terraform_examples/positive2.tf[49,0]
Expected value: aws_lb[{{test}}].drop_invalid_header_fields should be set to true
Actual value: aws_lb[{{test}}].drop_invalid_header_fields is missing
Review result in Checkmarx One: ALB Not Dropping Invalid Headers
Reactions are currently unavailable