Skip to content

Investigate possibility of code injection attacks #17

@ghost

Description

This is vague fear I have about expoing cfn_nag a service.... it takes arbitrary json/yml.... and then on the backend there is a lot of eval magic with rules and such. Need to spend some quality time to see if there a code injection exploit or at least make sure we are doing the strictest lockdown/parse of the json/yml as possible.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions