Description
With container_access_type set to blob or container, an Azure Storage Container permits unauthenticated Blob reads if the account allows anonymous access and the network permits connectivity. Private files or internal artifacts can be exposed.
blob permits anonymous reads of Blob contents; container also permits listing the container’s Blobs. These public-access levels do not grant anonymous write permission.
Potential impact
- Internal documents or files may be read without authentication.
- The container access level can reveal stored file names and structure through Blob listing.
Remediation
Set container_access_type to private for containers that do not need public access. Disable Blob public access on the account too when no anonymous access is required. Apply authentication and least privilege to data access, and separate intentionally public data. Verify intended client access and rejection of anonymous requests.
Examples
These excerpts change the access level of the same container. They use provider syntax that supports storage_account_name; account settings are omitted.
Before
resource "azurerm_storage_container" "artifact_container" {
name = "vhds"
storage_account_name = azurerm_storage_account.example.name
container_access_type = "blob"
}
The blob level permits anonymous reads of Blob contents when the account and network allow them.
After
resource "azurerm_storage_container" "artifact_container" {
name = "vhds"
storage_account_name = azurerm_storage_account.example.name
container_access_type = "private"
}
private does not permit anonymous reads from the container. Manage access by authenticated users or valid SAS tokens separately.