Nifcloud Computing Undefined Security Group To Instance

  • Query id: 89218b48-75c9-4cb3-aaba-5299e852e8bc
  • Query name: Nifcloud Computing Undefined Security Group To Instance
  • Platform: Terraform
  • Severity: High
  • Category: Networking and Firewall
  • CWE: 285
  • URL: Github

Description

Missing security group for instance
Documentation

Code samples

Code samples with security vulnerabilities

Positive test num. 1 - tf file
resource "nifcloud_instance" "positive" {
  image_id        = data.nifcloud_image.ubuntu.id
  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}

Code samples without security vulnerabilities

Negative test num. 1 - tf file
resource "nifcloud_instance" "negative" {
  image_id        = data.nifcloud_image.ubuntu.id
  security_group  = nifcloud_security_group.example.group_name
  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}