duo-labs / duo-labs/cloudmapper

Identify concerns if a malicious account were scanned

Open
#593 0 comments 0 reactions 0 assignees View on GitHub
audit
Dominant language
JavaScript
Stars
6.3k
Forks
836
PR merge metrics
No merged PRs in 30d

Description

In developing CloudMapper, I have not really considered the idea of what would happen if a malicious account were scanned. Specifically, could it be possible to cause something like XSS if someone names an IAM user (or other resources) maliciously, such that when a report is generated, that it somehow can do something unexpected? Are there other areas that could be impacted by a malicious attacker? Are there mitigations I can put in place?

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.