Control: Application Gateway should restrict message lookup in Log4j2
Description
This control checks that Application Gateway restricts message lookup in Log4j2 due to the CVE-2021-44228 vulnerability, also known as log4jshell.
Usage
Run the control in your terminal:
powerpipe control run terraform_azure_compliance.control.application_gateway_restrict_message_lookup_log4j2
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run terraform_azure_compliance.control.application_gateway_restrict_message_lookup_log4j2 --share
SQL
This control uses a named query:
application_gateway_restrict_message_lookup_log4j2