Description
Azure Storage can accept HTTP requests when secure transfer is not required. Clients using HTTP can expose data and credentials in transit.
Potential impact
An observer able to intercept unencrypted requests may read data or SAS tokens.
Remediation
Set https_traffic_only_enabled = true and configure clients to use HTTPS. For file shares, also verify encrypted SMB connections.
Examples
These excerpts use the current AzureRM secure-transfer option.
Before
hcl
resource "azurerm_storage_account" "example" {
name = "example1"
resource_group_name = data.azurerm_resource_group.example.name
location = data.azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
https_traffic_only_enabled = false
}
After
hcl
resource "azurerm_storage_account" "example" {
name = "example"
resource_group_name = data.azurerm_resource_group.example.name
location = data.azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
https_traffic_only_enabled = true
}