Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Amazon Inspector can now scan AWS Lambda Functions

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Amazon Inspector can now scan AWS Lambda Functions


๐Ÿ’ก Newskategorie: Programmierung
๐Ÿ”— Quelle: dev.to

Amazon Inspector, a service focused on automated vulnerability scanner that continuously scans AWS workloads for vulnerabilities is now supporting scanning for AWS Lambda functions.

Amazon Inspector supports scanning of AWS Lambda functions and Lambda layers with Java, NodeJS and Python runtimes.

Need for vulnerability checks

Often times, we have code which depends on many packages from installed via different package managers which are prone to security leaks. Although, updating to new version could resolve it, you might have dependencies which are still prone to vulnerabilities. The best way to address is a regular scanning of your codebase to ensure there aren't serious issues.

Serverless specific, until now we had to depend on a third party tool to scan but now it's possible with Amazon Inspector

Enabling Inspector

First off, you would have to enable Inspector for your AWS Account.
Enabling Inspector for your account

Your first scan

Once enabled, you will need a few minutes for Amazon Inspector to scan across your resources across Amazon EC2 instances, Amazon ECR images and now AWS Lambda functions and Lambda layers.

After Amazon Inspector has scanned you can view the report on Inspector dashboard.
Amazon Inspector dashboard of all vulnerabilities

[Fun Fact] As you can see, I don't have a single EC2 instance running on this AWS Account.

Scanned findings

Inspector found that 9 of my Lambda functions had a vulnerabilities with critical, high and medium levels.
Inspector findings by Lambda functions

If you click on one of the functions, you can find the summary for vulnerabilities in that specific AWS Lambda function or the vulnerability because of using an AWS Lambda layer.

Summary for a Lambda function

Findings for a Lambda function

Let's dive into the finding

One of the vulnerability is with Axios NPM package.
Vulnerability with Axios

This also gives details about axios package and the affected with fixed version.
Affected packages

Inspector provides you the complete details of the vulnerability along with the link to National Vulnerability Database (NVD) report.
Vulnerability details

Along the details, you can also find how to fix it with the available remedy.
Remedy to fix the vulnerability
In this case, it's updating axios version.

Another way to understand the severity of the vulnerability, the score from National Vulnerability Database (NVD) and Inspector is available.
Inspector score

Pricing

Amazon Inspector is available as part of free trial for 15 days.
For Lambda scans alone, there is monthly based on average number of Lambda functions scanned per month and price is prorated based on total Inspector coverage hours for the month.

More details on Amazon Inspector Pricing.

Action time!

Now it's time to scan your Lambda functions and layers with Amazon Inspector.
Time for scans now

...



๐Ÿ“Œ Amazon Inspector can now scan AWS Lambda Functions


๐Ÿ“ˆ 74.05 Punkte

๐Ÿ“Œ AWS' Inspector offers vulnerability management for Lambda serverless functions


๐Ÿ“ˆ 50.48 Punkte

๐Ÿ“Œ Serverless Prey - Serverless Functions For Establishing Reverse Shells To Lambda, Azure Functions, And Google Cloud Functions


๐Ÿ“ˆ 49.58 Punkte

๐Ÿ“Œ How to optimize your lambda functions with AWS Lambda power tuning


๐Ÿ“ˆ 48.85 Punkte

๐Ÿ“Œ AWS Inspector for AWS Lambda


๐Ÿ“ˆ 46.53 Punkte

๐Ÿ“Œ Building an AI powered and Serverless meal planner with OpenAI, AWS Step functions, AWS Lambda and CDK


๐Ÿ“ˆ 41.66 Punkte

๐Ÿ“Œ Applying event filters to AWS Lambda Functions with the AWS CDK


๐Ÿ“ˆ 41.66 Punkte

๐Ÿ“Œ AWS Lambda support Node.js 18 now. Should we update the version of Node.js in the Lambda runtime?


๐Ÿ“ˆ 41.61 Punkte

๐Ÿ“Œ Lambda.sh | Haskell-like lambda functions in bash


๐Ÿ“ˆ 41.22 Punkte

๐Ÿ“Œ Supercharge Your AWS Lambda Game With Lambda Powertools


๐Ÿ“ˆ 37.26 Punkte

๐Ÿ“Œ AWS: Integrating OpenAPI With the Amazon API Gateway and Lambda Functions


๐Ÿ“ˆ 37.22 Punkte

๐Ÿ“Œ Functions of Commercial Bank: Primary Functions and Secondary Functions


๐Ÿ“ˆ 34.76 Punkte

๐Ÿ“Œ Hacking Serverless Runtimes: Profiling AWS Lambda Azure Functions & More


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Should you select Azure Functions or AWS Lambda?


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Should you select Azure Functions or AWS Lambda?


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Cook a recipe with AWS: Simple and Easy Lambda Functions


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Python and relative imports in AWS Lambda Functions


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Guide to Building AWS Lambda Functions from ECR Images to Manage SageMaker Inference Endpoints


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Demystifying AWS Lambda Functions


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Modifying Application Behavior with Go Lambda Functions and AWS AppConfig Feature Flags


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Bluemix OpenWhisk: IBM stellt Konkurrenten zu AWS Lambda und Google Cloud Functions vor


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Bluemix OpenWhisk: IBM stellt Konkurrenten zu AWS Lambda und Google Cloud Functions vor


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Learn How to Write AWS Lambda Functions with Three Architecture Layers


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Bundling Go Lambda Functions with the AWS CDK


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Developing AWS Lambda Functions In Locally


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ ESP32 to AWS: Complete IoT Solution with IoT Core, DynamoDB, and Lambda Functions in Golang


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Analyze and debug Quarkus based AWS Lambda functions with X-Ray


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Guide to Creating Lambda Functions within AWS CDK Constructs


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ How to save costs using AWS Lambda SnapStart for Java based functions


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Deploying Java Serverless Functions as AWS Lambda


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ How to access Neon Postgres from AWS Lambda functions via serverless driver


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Cold Start Challenge in AWS Lambda Functions


๐Ÿ“ˆ 34.03 Punkte

๐Ÿ“Œ Using AWS Lambda & Node.js to scan your S3 uploads


๐Ÿ“ˆ 33.94 Punkte

๐Ÿ“Œ Connecting AWS Lambda with Amazon RDS using AWS CDK and Node.js


๐Ÿ“ˆ 33.26 Punkte

๐Ÿ“Œ Datadog now supports Amazon EFS for AWS Lambda on Amazon Web Services


๐Ÿ“ˆ 33.17 Punkte











matomo