developmentseed / developmentseed/titiler-lambda-layer
Security Concern: Unrestricted S3 Access in Titiler Policy
- 主要语言
- Python
- 星标
- 17
- 派生
- 4
- PR 合并指标
- 30 天内没有已合并 PR
描述
The CloudFormation template ([sam.yml](https://github.com/developmentseed/titiler-lambda-layer/blob/main/sam.yml)) you provided grants the Lambda function [unrestricted access to all S3 buckets](https://github.com/developmentseed/titiler-lambda-layer/blob/main/sam.yml?plain=1#L57) through the policy associated with the [AWSLambdaExecute](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSLambdaExecute.html) statement. This presents a significant security risk, as the application might unintentionally access or modify data in buckets unrelated to its intended operations. This could potentially expose sensitive information or disrupt critical business processes.
- Recommendations:
1) Refactor the policy: Use a least privilege approach by specifying the exact S3 buckets the function requires access to instead of using wildcards (*).
2) Consider IAM roles: Utilize IAM roles to grant specific permissions to the Lambda function instead of relying on the broader AWSLambdaExecute policy.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。