RDS-associated security group has an unrestricted ingress range

Limit inbound access through an RDS security group to the required clients and database port.

Description

Allowing 0.0.0.0/0 or ::/0 as a source in a security group associated with an RDS instance applies the rule to every IPv4 or IPv6 address, respectively. Limit ingress to clients that need to connect to the database.

Actual external connectivity depends on the allowed port, the database's listening port, public addressing and network paths. Broad ingress permissions do not replace database authentication or authorization, but network controls should also restrict access to the required clients.

Potential impact

  • If an ingress rule permits the actual database port and a public connection path exists, clients across the unrestricted address range can attempt to connect to the database.
  • Allowing unnecessary external connections can expose the service to brute-force attempts or attacks using leaked credentials. Whether data can be read or changed still depends on authentication and database permissions.

Remediation

  • Identify the actual database port and required clients. Limit ingress to that port and the required source security groups or narrow CIDRs. A range is not trusted merely because it is more specific than /0.
  • Review PubliclyAccessible, subnets, routing, and actual security-group associations together. Where the architecture requires private connectivity, establish that path before changing public-access settings. Check authentication and database permissions separately.
  • Verify that the deployed instance uses the intended security groups. After the change, confirm that required clients can connect and connections from other sources are denied.

Examples

These examples compare allowed source ranges and omit properties needed for a complete deployment, such as the database engine. Port 80 is an example value; use the port required by the actual database.

Example using the full IPv4 range

yaml
Resources:
  DBEC2SecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Open database for access
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0
  DBInstance:
    Type: AWS::RDS::DBInstance
    Properties:
      PubliclyAccessible: true
      VPCSecurityGroups:
        - !GetAtt DBEC2SecurityGroup.GroupId

Example using a narrower CIDR

yaml
Resources:
  DBEC2SecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Open database for access
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 1.2.3.4/24
  DBInstance:
    Type: AWS::RDS::DBInstance
    Properties:
      PubliclyAccessible: true
      VPCSecurityGroups:
        - !GetAtt DBEC2SecurityGroup.GroupId

Explanation:

  • First example: CidrIp: 0.0.0.0/0 allows incoming traffic to port 80 from every IPv4 address. Check the database port and network paths together to determine actual database connectivity.
  • Second example: 1.2.3.4/24 describes the 1.2.3.0/24 network, not one host. It is not a recommended trusted range; replace it with the source range required by your clients.

References