logo

Database

Aws Public Clusters

Description

Detects AWS Redshift clusters that are publicly accessible from the internet. Public Redshift clusters can be accessed directly from the internet without requiring VPN or private network connectivity, which could expose sensitive data to unauthorized access if not properly secured.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Checks each Redshift cluster in the specified AWS region

    Reports a vulnerability if a cluster has PubliclyAccessible setting set to True

    Captures the cluster's namespace ARN and public accessibility status in the vulnerability report

Severity v4.0

1.3

Low

Method ID

CSPM-BPUHB

Technique

CSPM

Target

AWS

Technology

REDSHIFT

CWE ID(s)

CWE-306