False positive for AZU-0012 if deny set on azurerm_storage_account_network_rules instead of azurerm_storage_account #10120
Closed
ricohomewood
started this conversation in
False Detection
Replies: 1 comment
-
|
Hi @ricohomewood ! Thanks for the report. Track #10160 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
AVD-AZU-0012
Description
We set a
default_action = "Deny"on aazurerm_storage_account_network_rulesresource for the storage account not on the actualazurerm_storage_accountresource. However, trivy seems to ignore this fact and falsely assume we have not set it at all as it scans theazurerm_storage_accountbut not understanding this is set on theazurerm_storage_account_network_rules.Reproduction Steps
azurerm_storage_account_network_rules, for example:azurerm_storage_accountresource, which it shouldn't becuse it should detects its set via theazurerm_storage_account_network_rulesresource for that storage account:trivy config . --checks-bundle-repository mirror.gcr.io/aquasec/trivy-checks:2.1.1...
Target
Filesystem
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions