Skip to content

bug(scan): ECS Task Definition Volume Not Encrypted - Is encrypted #7422

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
scott2889 opened this issue Apr 2, 2025 · 0 comments
Open
Labels
aws PR related with AWS Cloud bug Something isn't working community Community contribution

Comments

@scott2889
Copy link

  • Describe in details what the problem is

A critical vulnerability is being raised telling us 'AWS ECS Task Definition EFS data in transit between AWS ECS host and AWS EFS server should be encrypted' - however the data IS encrypted

  • Attach a log file with relevant data preferably in DEBUG level (--log-level=DEBUG)

SAST report shows the exact error is AWS ECS Task Definition EFS data in transit between AWS ECS host and AWS EFS server should be encrypted
Its specifically referring to the attribute: transit_encryption = "ENABLED"
This attribute IS enabled

  • Attach the scanned sample files, anonymize the data if the original file cannot be provided
  • When attaching files to the issue make sure they are properly formatted

Expected Behavior

For this not to be reported as a vulnerability

Actual Behavior

reported as a vulnerability

Steps to Reproduce the Problem

Specifications

(N/A if not applicable)

  • Version:
  • Platform: GitLab
  • Subsystem: CI/CD Pipeline
@scott2889 scott2889 added bug Something isn't working community Community contribution labels Apr 2, 2025
@github-actions github-actions bot added the aws PR related with AWS Cloud label Apr 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
aws PR related with AWS Cloud bug Something isn't working community Community contribution
Projects
None yet
Development

No branches or pull requests

1 participant