Issue search
Which component is affected?
Prowler CLI/SDK
Cloud Provider (if applicable)
Azure
Steps to Reproduce
- Create an NSG with one inbound rule that allows Any protocol from the Internet:
az network nsg create --resource-group <rg> --name nsg-udp-any
az network nsg rule create --resource-group <rg> --nsg-name nsg-udp-any \
--name any-from-internet --priority 100 --direction Inbound --access Allow \
--protocol '*' --source-address-prefixes Internet --destination-port-ranges '*'
Azure stores the rule with "protocol": "*" and "sourceAddressPrefix": "Internet".
- Run the check:
prowler azure --az-cli-auth --azure-resource-group <rg> --check network_udp_internet_access_restricted
For comparison, an otherwise identical rule with --protocol Udp is correctly reported as FAIL.
Expected behavior
FAIL. A rule with protocol Any (*) allows UDP, so every UDP port on the resources behind the NSG is reachable from the Internet.
Actual Result with Screenshots or Logs
PASS: "Security Group nsg-udp-any ... has UDP internet access restricted."
The fail condition only accepts "UDP" and "Udp":
rule.protocol in ["UDP", "Udp"]
https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/azure/services/network/network_udp_internet_access_restricted/network_udp_internet_access_restricted.py#L21
The SSH, RDP and HTTP checks in the same service already treat * as matching TCP (["TCP", "Tcp", "*"]), so the UDP check is the only one of the four that misses it.
How did you install Prowler?
Cloning the repository from github.com (git clone)
Environment Resource
Workstation
OS used
MacOS
Prowler version
5.40.0 (the affected line is unchanged on current master)
Python version
3.13.8
Pip version
N/A (uv-managed virtualenv)
Context
This is separate from #12854 and its PR #12866. Those cover the destination port condition in the SSH, RDP and HTTP checks. This bug is in the protocol condition of the UDP check, which #12866 does not touch, so the two fixes do not overlap.
I have a fix with a test ready and will open a PR shortly.
Issue search
Which component is affected?
Prowler CLI/SDK
Cloud Provider (if applicable)
Azure
Steps to Reproduce
Azure stores the rule with
"protocol": "*"and"sourceAddressPrefix": "Internet".For comparison, an otherwise identical rule with
--protocol Udpis correctly reported as FAIL.Expected behavior
FAIL. A rule with protocol Any (*) allows UDP, so every UDP port on the resources behind the NSG is reachable from the Internet.
Actual Result with Screenshots or Logs
PASS: "Security Group nsg-udp-any ... has UDP internet access restricted."
The fail condition only accepts
"UDP"and"Udp":https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/azure/services/network/network_udp_internet_access_restricted/network_udp_internet_access_restricted.py#L21
The SSH, RDP and HTTP checks in the same service already treat
*as matching TCP (["TCP", "Tcp", "*"]), so the UDP check is the only one of the four that misses it.How did you install Prowler?
Cloning the repository from github.com (git clone)
Environment Resource
Workstation
OS used
MacOS
Prowler version
5.40.0 (the affected line is unchanged on current master)
Python version
3.13.8
Pip version
N/A (uv-managed virtualenv)
Context
This is separate from #12854 and its PR #12866. Those cover the destination port condition in the SSH, RDP and HTTP checks. This bug is in the protocol condition of the UDP check, which #12866 does not touch, so the two fixes do not overlap.
I have a fix with a test ready and will open a PR shortly.