turbot/terraform_azure_compliance

Control: Application Gateway should restrict message lookup in Log4j2

Description

This control checks that Application Gateway restricts message lookup in Log4j2 due to the CVE-2021-44228 vulnerability, also known as log4jshell.

Usage

Run the control in your terminal:

powerpipe control run terraform_azure_compliance.control.application_gateway_restrict_message_lookup_log4j2

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run terraform_azure_compliance.control.application_gateway_restrict_message_lookup_log4j2 --share

SQL

This control uses a named query:

application_gateway_restrict_message_lookup_log4j2

Tags