Data Factory should not be publicly exposed
Severity | Exploitability | Providers | Categories |
---|---|---|---|
CRITICAL | MEDIUM | Azure | DATA |
Description
Data Factory services are publicly accessible. The default configuration for Data Factory access is public.
Impact
Potential data exposure | Visible in logs | User interaction required | Privileges required |
---|---|---|---|
True | False | False | False |
Public access to Data factory may lead to data breach, data tampering or DDoS (Distributed Denial-of-Service).
Remediation guidelines
Set public_network_enabled to false, to disable public access for Data Factory.