Issue: Missing HSTS headers on port 80 and 443
Issue: Privilege escalation possibilities through world writeable files in the crontab
Issue: Web application is vulnerable to a XSS and CSRF attack
Issue: TLS/SSL misconfiguration. Accepting CBC-ciphers and compression techniques such as GZIP, while also accepting TLS 1.0 and 1.1
Issue: Amazon EC2 data at rest encryption not configured
Issue: Azure Frontdoor (WAF) not correctly implemented