Slide 26
Slide 26 text
Ersteller, Datum, Dokumentenname, C2 General
26
Attack summary: Identified security risks
Critical: Server—Side Request Forgery (web app)
High: Improper Access Control (Key Vault access policy)
High: Insufficient separation of dev/prod environments (Key Vault)
Medium: Insecure credential management (SSH key reused)
Medium: Insecure default network configuration
Medium: Exposed management services