Skip to content

RFD - GitLab SAST scans report critical & high vulnerabilities for Nebari in AWS #55

@joneszc

Description

@joneszc
Status Draft 🚧 / Open for comments 💬
Author(s) @joneszc
Date Created 05-09-2024
Date Last updated dd-MM-YYY
Decision deadline N/A

Title

SAST Scans Show Nebari Has Critical/High Vulnerabilities in AWS

Summary

Of the several critical vulnerabilities reported by GitLab SAST for Nebari, deployed in AWS, some vulnerabilities could be mitigated by adding AWS Key Management Service (KMS) controls & configuration options in addition to applying encryption as default settings in the corresponding AWS services:

User benefit

Defense in Depth Security Strategy

Design Proposal

MITIGATION:

Alternatives or approaches considered (if any)

Best practices

User impact

Unresolved questions

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions