logo

Database

Aws No Sensitive Info Filter

Description

Detects Amazon Bedrock guardrails that do not have sensitive information filtering policies configured. Missing sensitive information filters could allow sensitive or personal data to be inadvertently exposed to foundation models, creating potential data privacy and security risks.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Retrieves all Bedrock guardrails in the specified AWS region

    For each guardrail, checks if the sensitiveInformationPolicy configuration is present

    Reports a vulnerability if a guardrail is found without a sensitive information policy configured

Severity v4.0

1.3

Low

Method ID

CSPM-5ESSI

Technique

CSPM

Target

AWS

Technology

BEDROCK

CWE ID(s)

CWE-306