logo

Database

Aws Elbv2 Deletion Protection Disabled

Description

Identifies Application Load Balancers (ALB) and Network Load Balancers (NLB) that have deletion protection disabled. Load balancers without deletion protection could be accidentally deleted, potentially causing service disruptions. This check excludes EKS-managed load balancers.

Weakness:

258 - Lack of protection against deletion - ELB

Category: Functionality Abuse

Detection Strategy

    Retrieves all ELBv2 load balancers in the AWS account and region

    Checks if the load balancer is not associated with an EKS cluster by examining its tags

    For non-EKS load balancers, examines the 'deletion_protection.enabled' attribute

    Reports a vulnerability if deletion protection is not set to 'true'

    Each vulnerability includes the load balancer ARN and the current protection setting value

Severity v4.0

4.6

Medium

Method ID

CSPM-EODOA

Technique

CSPM

Target

AWS

Technology

ELBV2

CWE ID(s)

CWE-732