Ensure that ALB drops HTTP headers

Error: ALB does not drop HTTP headers

Bridgecrew Policy ID: BC_AWS_NETWORKING_41
Checkov Check ID: CKV_AWS_131
Severity: MEDIUM

ALB does not drop HTTP headers

Description

TBA. Application Load Balancer (ALB)

Fix - Buildtime

Terraform

  • Resource: aws_alb
  • Argument: drop_invalid_header_fields
resource "aws_alb" "test_success" {
                    name               = "test-lb-tf"
                    internal           = false
                    load_balancer_type = "network"
                    subnets            = aws_subnet.public.*.id
 +                  drop_invalid_header_fields = true
                }

Did this page help you?