Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The document explicitly instructs users to replace the public domain with a PrivateLink endpoint domain and states that the endpoint only supports HTTP, not HTTPS. Even on a private network, HTTP removes transport encryption and weakens confidentiality and integrity guarantees, exposing requests and responses to interception or tampering by compromised internal hosts, misconfigured network devices, or lateral-movement adversaries.
