HTTP port is open to the Internet

Review whether HTTP port 80 needs public access and restrict internal services while protecting data in transit.

Description

A security group rule allowing TCP 80, commonly used for HTTP, from 0.0.0.0/0 includes every IPv4 source. Actual service access also requires public addressing, routing, and a listening service. This can be intentional for a public website or HTTPS redirect, but internal APIs and management pages do not need the same exposure.

HTTP does not encrypt traffic. Use HTTPS for sensitive information regardless of whether the service is public. A redirect alone does not protect the initial HTTP request.

Potential impact

  • External clients that can reach the service can scan it and attempt access.
  • Weak authentication or service vulnerabilities can enable unauthorized access, while HTTP traffic can be disclosed or modified along the network path.

Remediation

  • If public access is unnecessary, restrict sources to the actual service clients or management connections.
  • Use HTTPS for public web services and add load balancers or a WAF where appropriate. These controls do not replace application authentication and authorization.
  • Review all attached security groups and broad port-range rules, and separate management access from user traffic.

Examples

Replace the VPC and CIDR with values for the actual environment. Attaching the security group to the service is omitted.

Before

yaml
- name: 보안 그룹 생성
  amazon.aws.ec2_group:
    name: web-open
    description: open web security group
    vpc_id: vpc-12345
    rules:
      - proto: tcp
        ports: 80
        cidr_ip: 0.0.0.0/0

This permits TCP 80 from every IPv4 source.

After

yaml
- name: 보안 그룹 생성
  amazon.aws.ec2_group:
    name: web-internal
    description: restricted web security group
    vpc_id: vpc-12345
    rules:
      - proto: tcp
        ports: 80
        cidr_ip: 10.0.0.0/16

This narrows the allowed sources to a specified private CIDR. Check that it represents the clients that need access, and configure HTTPS separately. Because the group name changes, attach the new group and remove the existing broad allowance as well.

References