Ensure that automatic minor version upgrades are enabled on Amazon MQ brokers.
Risk
Amazon MQ brokers without automatic minor version upgrades may miss critical updates, leaving them vulnerable to security risks, bugs, and performance issues.
Run this check with Prowler CLI
prowler aws --checks mq_broker_auto_minor_version_upgrades
ARN template
arn:aws:mq:region:account-id:broker:broker-id
Remediation
aws mq update-broker --broker-id <broker-id> --auto-minor-version-upgrade
https://docs.prowler.com/checks/aws/general-policies/ensure-aws-mqbrokers-minor-version-updates-are-enabled/
https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MQ/auto-minor-version-upgrade.html
https://docs.aws.amazon.com/securityhub/latest/userguide/mq-controls.html#mq-3
Ensure that automatic minor version upgrades are enabled on Amazon MQ brokers to receive the latest security patches and improvements automatically.
Source Code
Resource Type
AwsAmazonMQBroker