CCSS (Common Configuration Scoring System) is a set of measures used to determine the severity of the rule.
Each rule is associated with a high-level category. For example IAM, Container, Monitoring, Logging, Network, etc.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsInbound traffic is allowed to a resource from any source instead of a restricted range and potentially everyone can access your resource.
Set properties.access
to Deny or
properties.sourceAddressPrefixto specific IP range only, e.g.
192.168.1.0/24`.
Set access
to Deny
, or source_address_prefix
to specific CIDR block range only, e.g. 192.168.1.0/24
.
resource "azurerm_network_security_rule" "allowed" {
name = "test123"
priority = 100
direction = "Inbound"
access = "Allow"
protocol = "Tcp"
source_port_range = "*"
destination_port_range = "*"
source_address_prefix = "192.168.1.0/24"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = "test"
}