You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR implements the “Bypasses Network Controls” risk category mentioned in #454.
As mentioned in the original issue, some IAM permissions can access resources through AWS managed control planes or service APIs (for example, redshift:GetClusterCredentials via the Redshift Query Editor), bypassing the need for direct network access. In these cases, security groups and NACLs are effectively bypassed.
Changes:
added a new BypassesNetworkControls risk category with its own severity + description
added a list of IAM actions that enable these control-plane/out-of-band access paths
surfaced these findings in PolicyFinding results + included them in ServicesAffected
added unit tests covering both PolicyFinding & scan_policy behavior to make sure detection is correct
(This essentially gives these permissions a dedicated place instead of forcing them into existing categories like data exfiltration/privilege escalation)
What gif best describes this PR or how it makes you feel?
Completion checklist
Additions and changes have unit tests
The pull request has been appropriately labeled using the provided PR labels
GitHub actions automation is passing (make test, make lint, make security-test, make test-js)
[N/A] If the UI contents or JavaScript files have been modified, generate a new example report:
# Generate the updated Javascript bundle
make build-js
# Generate the example report
make generate-report
Hi team, continuing on this thread on some findings i face in production findings, i couldn't rmb the exact permission,
Granted RDS.Read permission to Team (Developers), however, RDS has this feature to view logs from the console that expose raw SQL statement. The sensitive database raw logs should only be accessed by DBA from this bastion host protected by strict security groups. Because of this AWS permission, some of the data is accessed not only by DBA.
RDS OracleDB (only this type) data exfiltration. One AWS permission in OracleDB allows exfiltration to other accounts S3 even if we lockdown no outbound connection of the RDS in isolated subnet (ingress from app, no egress). DBA who have access to OracleDB, can exfiltrate oracle db data via AWS control plane to their own S3.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
This PR implements the “Bypasses Network Controls” risk category mentioned in #454.
As mentioned in the original issue, some IAM permissions can access resources through AWS managed control planes or service APIs (for example, redshift:GetClusterCredentials via the Redshift Query Editor), bypassing the need for direct network access. In these cases, security groups and NACLs are effectively bypassed.
Changes:
(This essentially gives these permissions a dedicated place instead of forcing them into existing categories like data exfiltration/privilege escalation)
What gif best describes this PR or how it makes you feel?
Completion checklist
make test,make lint,make security-test,make test-js)