diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md
index c8b892e2d1..1756ff0854 100644
--- a/prowler/CHANGELOG.md
+++ b/prowler/CHANGELOG.md
@@ -13,6 +13,12 @@ All notable changes to the **Prowler SDK** are documented in this file.
### 🐞 Fixed
- `load_and_validate_config_file` now unwraps namespaced config for every built-in and external provider, and no longer leaks the full file as the provider's config when the file is namespaced [(#10700)](https://github.com/prowler-cloud/prowler/pull/10700)
+=======
+- `elbv2_alb_drop_invalid_header_fields_enabled` check for AWS provider, verifying Application Load Balancers have `routing.http.drop_invalid_header_fields.enabled` set to `true` to mitigate HTTP desync attacks (AWS FSBP ELB.4) [(#11471)](https://github.com/prowler-cloud/prowler/pull/11471)
+- GCP `logging_sink_created` now recognizes organization-level aggregated sinks with `includeChildren=True`, avoiding false failures for covered projects [(#11355)](https://github.com/prowler-cloud/prowler/pull/11355)
+- Jira integration no longer fails with `400 INVALID_INPUT` when a finding has empty fields [(#11474)](https://github.com/prowler-cloud/prowler/pull/11474)
+- GCP `iam_service_account_unused` now passes disabled service accounts instead of failing them, since a disabled account cannot authenticate or be used [(#11467)](https://github.com/prowler-cloud/prowler/pull/11467)
+- AWS AI Security Framework now renders in the dashboard instead of showing "No data found for this compliance", by adding the missing compliance view module [(#11470)](https://github.com/prowler-cloud/prowler/pull/11470)
---
diff --git a/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json b/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json
index a64a421c8a..cea7ad1655 100644
--- a/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json
+++ b/prowler/compliance/aws/aws_foundational_security_best_practices_aws.json
@@ -1863,7 +1863,9 @@
"Id": "ELB.4",
"Name": "Application load balancers should be configured to drop HTTP headers",
"Description": "This control evaluates AWS Application Load Balancers (ALB) to ensure they are configured to drop invalid HTTP headers. The control fails if the value of routing.http.drop_invalid_header_fields.enabled is set to false. By default, ALBs are not configured to drop invalid HTTP header values. Removing these header values prevents HTTP desync attacks.",
- "Checks": [],
+ "Checks": [
+ "elbv2_alb_drop_invalid_header_fields_enabled"
+ ],
"Attributes": [
{
"ItemId": "ELB.4",
diff --git a/prowler/lib/outputs/jira/jira.py b/prowler/lib/outputs/jira/jira.py
index ed8f7faab0..f7f31666e1 100644
--- a/prowler/lib/outputs/jira/jira.py
+++ b/prowler/lib/outputs/jira/jira.py
@@ -229,7 +229,9 @@ class MarkdownToADFConverter:
return node
def _paragraph_with_text(self, text: str) -> Dict:
- return {"type": "paragraph", "content": [self._create_text_node(text, None)]}
+ # ADF forbids empty text nodes; emit an empty paragraph instead.
+ content = [self._create_text_node(text, None)] if text else []
+ return {"type": "paragraph", "content": content}
@staticmethod
def _pop_mark(marks_stack: List[Dict], mark_type: str) -> None:
@@ -1118,6 +1120,18 @@ class Jira:
tenant_info: str = "",
) -> dict:
+ # ADF forbids empty text nodes, so Jira rejects them with 400 INVALID_INPUT.
+ def _safe(value: str) -> str:
+ return value if (value and value.strip()) else "-"
+
+ check_id = _safe(check_id)
+ check_title = _safe(check_title)
+ status_extended = _safe(status_extended)
+ provider = _safe(provider)
+ region = _safe(region)
+ resource_uid = _safe(resource_uid)
+ resource_name = _safe(resource_name)
+
table_rows = [
{
"type": "tableRow",
diff --git a/prowler/providers/aws/services/elbv2/elbv2_alb_drop_invalid_header_fields_enabled/__init__.py b/prowler/providers/aws/services/elbv2/elbv2_alb_drop_invalid_header_fields_enabled/__init__.py
new file mode 100644
index 0000000000..e69de29bb2
diff --git a/prowler/providers/aws/services/elbv2/elbv2_alb_drop_invalid_header_fields_enabled/elbv2_alb_drop_invalid_header_fields_enabled.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_alb_drop_invalid_header_fields_enabled/elbv2_alb_drop_invalid_header_fields_enabled.metadata.json
new file mode 100644
index 0000000000..0293501578
--- /dev/null
+++ b/prowler/providers/aws/services/elbv2/elbv2_alb_drop_invalid_header_fields_enabled/elbv2_alb_drop_invalid_header_fields_enabled.metadata.json
@@ -0,0 +1,40 @@
+{
+ "Provider": "aws",
+ "CheckID": "elbv2_alb_drop_invalid_header_fields_enabled",
+ "CheckTitle": "Application Load Balancer should be configured to drop invalid HTTP header fields",
+ "CheckType": [
+ "Software and Configuration Checks/AWS Security Best Practices/Network Reachability",
+ "Software and Configuration Checks/Industry and Regulatory Standards/AWS Foundational Security Best Practices",
+ "TTPs/Initial Access",
+ "Effects/Data Exposure"
+ ],
+ "ServiceName": "elbv2",
+ "SubServiceName": "",
+ "ResourceIdTemplate": "",
+ "Severity": "medium",
+ "ResourceType": "AwsElbv2LoadBalancer",
+ "ResourceGroup": "network",
+ "Description": "Ensure that Application Load Balancers (ALB) are configured to drop invalid HTTP header fields. The check fails when `routing.http.drop_invalid_header_fields.enabled` is not set to `true`. By default, ALBs do not remove HTTP headers that do not conform to RFC 7230.",
+ "Risk": "Forwarding non-RFC-compliant HTTP headers to backend targets enables HTTP desync (request smuggling):\n- **Confidentiality**: session/token theft, data exfiltration\n- **Integrity**: cache poisoning, request routing bypass, unauthorized actions\n- **Availability**: backend exhaustion.\nDropping invalid header fields removes a primary smuggling vector.",
+ "RelatedUrl": "",
+ "AdditionalURLs": [
+ "https://docs.aws.amazon.com/elasticloadbalancing/latest/application/application-load-balancers.html#drop-invalid-header-fields",
+ "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-4"
+ ],
+ "Remediation": {
+ "Code": {
+ "CLI": "aws elbv2 modify-load-balancer-attributes --load-balancer-arn + No providers have been configured. Start by setting up a provider. +
+- No providers have been configured. Start by setting up a provider. -
-