Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFD - GitLab SAST scans report critical & high vulnerabilities for Nebari in AWS #55

Open
joneszc opened this issue Sep 5, 2024 · 0 comments

Comments

@joneszc
Copy link

joneszc commented Sep 5, 2024

Status Draft 🚧 / Open for comments 💬
Author(s) @joneszc
Date Created 05-09-2024
Date Last updated dd-MM-YYY
Decision deadline N/A

Title

SAST Scans Show Nebari Has Critical/High Vulnerabilities in AWS

Summary

Of the several critical vulnerabilities reported by GitLab SAST for Nebari, deployed in AWS, some vulnerabilities could be mitigated by adding AWS Key Management Service (KMS) controls & configuration options in addition to applying encryption as default settings in the corresponding AWS services:

User benefit

Defense in Depth Security Strategy

Design Proposal

MITIGATION:

Alternatives or approaches considered (if any)

Best practices

User impact

Unresolved questions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant