Skip to content

ALB Not Dropping Invalid Headers @ /terraform_examples/positive2.tf #78

@Yoavast

Description

@Yoavast

Checkmarx (IaC-Security): ALB Not Dropping Invalid Headers
Applications: yael's application
Checkmarx Project: Yoavast/CX-AST
Repository URL: https://github.com/Yoavast/CX-AST
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: b70b7227-90db-4075-88cb-4c196077be97


It's considered a best practice when using Application Load Balancers to drop invalid header fields

Locations:

    File: /terraform_examples/positive2.tf[49,0]
    Expected value: aws_lb[{{test}}].drop_invalid_header_fields should be set to true
    Actual value: aws_lb[{{test}}].drop_invalid_header_fields is missing
    Review result in Checkmarx One: ALB Not Dropping Invalid Headers

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions