🎄 Join our Annual Holiday wargame and win prizes!


Loadbalancer HTTP allowed

Using plain HTTP is insecure, as it transmits data in an unencrypted and readable format. This weakness exposes data to potential eavesdropping.

Recommendation

Only allow HTTPS for Load Balancer. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/lb_listener

Metadata

  • Severity: informational
  • Slug: loadbalancer-http-allowed

CWEs

  • 319: Cleartext Transmission of Sensitive Information

Available Labs

Open Aws labs in SecDim Play for this vulnerability.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more