azure-frontdoor-rules-engine-header-values

Rules Engine request/response header values may hard-code authorization credentials.

azurecritical service: azure:frontdoor emits ContainsSecret

Where it sits

locationMicrosoft.Cdn/profiles/ruleSets/rules.properties.actions[].parameters.{headerName,value}
location kindconfig_field
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceFront Door / CDN (azure:frontdoor)

Collection recipe

access moderead_api
operationRules - Get
response pathproperties.actions[].parameters
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Cdn/profiles/ruleSets/rules/read

References

move · open · esc close