Use of insecure channel - Source code
Description
Customer information is transmitted over a channel that does not use encryption.
Impact
- Capture sensitive information and credentials in plain text. - Intercept communication and steal or forge requests and responses.
Recommendation
Deploy the application over an encrypted communication channel, e.g. HTTPS using TLS.
Threat
Anonymous attacker in adjacent network executing a man-in-the-middle attack.
Expected Remediation Time
⏱️ 60 minutes.
Requirements
181 - Transmit data using secure protocolsRules
Ruby Insecure Openuri Http RequestJava Datasource Encryption DisabledDocker Jmxremote Ssl Disabled In EnvKotlin Cleartext Connection SpecDart Socket Insecure Tcp UseJava Unencrypted Socket ConnectionC Sharp Oauth Allow Insecure Http TrueJava Http Url In PropertiesTerraform Insecure Http PortJson Yaml Insecure Http PortJson Yaml Insecure Tcp Protocol UsageTerraform Tcp Ingress On Http PortJson Yaml Gateway Server Uses HttpJson Yaml Ssl Disabled In ConfigJava Unsafe Tls Renegotiation EnabledJava Jdbc Url Ssl Disabled