Skip to main content

CodeBuild build artifacts encryption should not be disabled

SeverityExploitabilityProvidersCategories
HIGHHIGHAWSDATA, PERMISSION

Description

CodeBuild uses artifacts such as a cache, logs, exported raw test report data files, and build results. Those should always be encrypted to protect the data if accesses are compromised.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseTrue

An attacker could read the CodeBuild build artifacts if it gains access to the AWS account.

Remediation guidelines

Do not disable the CodeBuild build artifacts encryption.

References

How can I help you ?