Description
site_config.ftps_state = "AllAllowed" permits unencrypted FTP as well. Using plaintext FTP can expose credentials and file contents in transit. Restrict required file transfers to FTPS, or disable the FTP feature when it is unused.
Potential impact
An attacker able to observe or alter plaintext traffic may target publishing credentials and deployment files.
Remediation
Set site_config.ftps_state to FtpsOnly, or Disabled when FTP is unnecessary. Verify that clients use TLS and validate the server certificate, and restrict and manage publishing credentials. Check authentication and transport protection on any alternative deployment path.
Examples
These examples use the legacy AzureRM 3.x azurerm_app_service resource. Current Linux and Windows Web App resources also expose the FTP state setting.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
ftps_state = "AllAllowed"
}
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
ftps_state = "FtpsOnly"
}
}
The revision permits FTPS only. This protects the file-transfer channel; it does not replace HTTPS-only settings or user authentication for the web app.