High severity CSPM issues (18)
Severity Non-Compliance Region Resource Issue Remediation Read more Action
Kubernetes / Registries High westus2 test-cluster Kubernetes Service Cluster has the version of Kubernetes 1.21.9, while node pool "agentpool" has version 1.21.7. Upgrade the version of Kubernetes on all node pools to the same version as the Service Cluster. More info
Cosmos DB High westus3 prevasio-cosmo-db-account2 Cosmos DB Account does not have Advanced Threat Protection enabled. To prevent attempts to exploit your Cosmos DB account resources, make sure your Cosmos DB Accounts have the Advanced Threat Protection feature enabled. More info
PostgreSQL High eastus2 prevasio-postgresql-server PostgreSQL Server has no geo-redundant backup storage enabled. To allow you to restore your PostgreSQL Servers to a different Azure region in the event of a regional outage or a disaster, ensure the geo-redundant backups are enabled for all PostgreSQL Database Servers. More info
PostgreSQL High CIS 4.3.1 PCI DSS 4.2 HIPAA (Encryption) eastus2 prevasio-postgresql-server PostgreSQL Server is not configured to have its data in-transit encrypted. To fulfill HIPAA requirements for all data to be transmitted over secure channels, ensure that PostgreSQL Server is set to use SSL for data transmission. More info
PostgreSQL High eastus2 prevasio-postgresql-server PostgreSQL Server does not have a sufficient log retention period: 1 day, while the recommended minimum is 4 days or more. For reliability and compliance purposes, ensure that all your PostgreSQL Servers have a sufficient log retention period, i.e. greater than 3 days. More info
PostgreSQL High eastus2 prevasio-postgresql-server PostgreSQL Server has Storage Auto-Growth feature disabled. To prevent your PostgreSQL Servers from running out of storage and becoming read-only, ensure that all your PostgreSQL Servers have Storage Auto-Growth feature enabled. More info
Cache for Redis High PCI DSS 4.2 HIPAA (Encryption) westus2 prevasio2 Redis Cache is not configured to use SSL connection. To fulfill HIPAA requirements for all data to be transmitted over secure channels, ensure that the SSL connection to your Redis Cache servers is enabled. More info
MySQL High CIS 4.4.1 PCI DSS 4.2 HIPAA (Encryption) eastus prevasio-mysql-server MySQL Server is not configured to have its data in-transit encrypted. To fulfill HIPAA requirements for all data to be transmitted over secure channels, ensure that MySQL Server is set to use SSL for data transmission. More info
Compute High eastus test-vm Virtual Machine does not have Just-in-Time (JIT) access enabled. To allow you to lock down inbound traffic to your VMs and reduce exposure to attacks while providing easy SSH/RDP access when needed, make sure the VMs have JIT access enabled. More info
Compute High eastus test-scale-set Virtual Machine Scale Set is not in multiple availability zones. To protect your VM scale sets from datacenter-level failures, ensure that your VM scale sets are using zone-redundant availability configurations instead of single-zone (zonal) configurations. More info
Compute High westus2 test-vm2 Virtual Machine has password authentication enabled. To remove the ability for remote attackers to brute-force credentials, ensure that your VMs are configured to use SSH keys instead of username/password credentials for SSH authentication. More info
Compute High westus2 empty-scale-set Virtual Machine Scale Set is not in multiple availability zones. To protect your VM scale sets from datacenter-level failures, ensure that your VM scale sets are using zone-redundant availability configurations instead of single-zone (zonal) configurations. More info
Compute High westus2 test-scale-set2 Virtual Machine Scale Set is not in multiple availability zones. To protect your VM scale sets from datacenter-level failures, ensure that your VM scale sets are using zone-redundant availability configurations instead of single-zone (zonal) configurations. More info
Web High eastus prevasio-web-app Web application has remote debugging enabled. To enhance security and protect the applications from unauthorized access, ensure that your App Services web applications have remote debugging disabled. More info
SQL High CIS 4.1.2 eastus prevasio-sql-server SQL Server is open to outside traffic. In order to eliminate the exposure from the public Internet, ensure that your SQL Database Servers are accessible through private endpoints instead of public IP addresses or service endpoints. More info
SQL High westus prevasio-sql-server2 SQL Server has no list of emails configured to which alerts could be sent upon detection of anomalous activities. To send alerts on unusual activity, vulnerabilities, and threats, specify email address(es) under "Send alerts to" in Advanced Threat Protection settings of Microsoft Defender for SQL. More info
Security High CIS 8.5 eastus prevasio-key-vault-2 Key Vault has no Purge Protection and therefore, is not recoverable. To prevent permanent deletion/purging of encryption keys, secrets and certificates stored within the Key Vaults, ensure that all Key Vaults have Purge Protection enabled. More info
Management & Governance High CIS 2.6 global SecurityCenterBuiltIn The default set of policies monitored by Defender for Cloud contains 1 disabled policy. To meet security and compliance requirements, ensure that all security policies (specified as parameters) provided by Defender for Cloud default policy (ASC Default) are enabled. More info
High severity private container images (1)
Repository Image tag Region Image size Pushed at Latest Vulnerabilities Alerts Action
cmotta2016/apache latest eastus 115.11 MB 17 High + 1,406 others (details) Runs HTTPS Web server on port 443 (details)
Runs HTTP Web server on port 80 (details)
High severity public container images (0)
Repository Image tag Region Image size Pushed at Latest Vulnerabilities Alerts Action