🚀 Join our AI Wargame at Black Hat Asia and our Workshop + Wargame at NDC Sydney .


RDS Unencrypted at Rest

In the absence of encryption at rest, compromised data can be easily read. RDS Database instances encryption at rest enhances data protection by safeguarding against unauthorised access to the underlying storage.

Remediation

Enable encryption for RDS instances. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance

Metadata

  • Severity: informational
  • Slug: rds-unencrypted-at-rest

CWEs

  • 325: Missing Cryptographic Step

OWASP

  • A02:2021: Cryptographic Failures

Available Labs

Open Aws labs in SecDim Play for this vulnerability.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more