logo

Database

Aws Insecure Transport

Description

Detects S3 buckets that may allow insecure data transmission over HTTP instead of HTTPS. This creates a security risk by potentially exposing data to interception during transit since HTTP traffic is unencrypted.

Weakness:

281 - Use of an insecure channel - Cloud Infrastructure

Category: Information Collection

Detection Strategy

    Examines the bucket policy of each S3 bucket in the AWS account

    Checks if the bucket policy includes statements that enforce secure transport (HTTPS)

    Reports a vulnerability if a bucket policy allows access without requiring secure transport

    Evaluates the 'Statement' section of bucket policies to identify missing or inadequate secure transport requirements

Severity v4.0

0.6

Low

Method ID

CSPM-2PI3R

Technique

CSPM

Target

AWS

Technology

S3

CWE ID(s)

CWE-319