Description
Allowing 0.0.0.0/0 or ::/0 as a source in a security group associated with an RDS instance applies the rule to every IPv4 or IPv6 address, respectively. Limit ingress to clients that need to connect to the database.
Actual external connectivity depends on the allowed port, the database's listening port, public addressing and network paths. Broad ingress permissions do not replace database authentication or authorization, but network controls should also restrict access to the required clients.
Potential impact
- If an ingress rule permits the actual database port and a public connection path exists, clients across the unrestricted address range can attempt to connect to the database.
- Allowing unnecessary external connections can expose the service to brute-force attempts or attacks using leaked credentials. Whether data can be read or changed still depends on authentication and database permissions.
Remediation
- Identify the actual database port and required clients. Limit ingress to that port and the required source security groups or narrow CIDRs. A range is not trusted merely because it is more specific than
/0. - Review
PubliclyAccessible, subnets, routing, and actual security-group associations together. Where the architecture requires private connectivity, establish that path before changing public-access settings. Check authentication and database permissions separately. - Verify that the deployed instance uses the intended security groups. After the change, confirm that required clients can connect and connections from other sources are denied.
Examples
These examples compare allowed source ranges and omit properties needed for a complete deployment, such as the database engine. Port 80 is an example value; use the port required by the actual database.
Example using the full IPv4 range
Resources:
DBEC2SecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Open database for access
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
DBInstance:
Type: AWS::RDS::DBInstance
Properties:
PubliclyAccessible: true
VPCSecurityGroups:
- !GetAtt DBEC2SecurityGroup.GroupId
Example using a narrower CIDR
Resources:
DBEC2SecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Open database for access
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 1.2.3.4/24
DBInstance:
Type: AWS::RDS::DBInstance
Properties:
PubliclyAccessible: true
VPCSecurityGroups:
- !GetAtt DBEC2SecurityGroup.GroupId
Explanation:
- First example:
CidrIp: 0.0.0.0/0allows incoming traffic to port80from every IPv4 address. Check the database port and network paths together to determine actual database connectivity. - Second example:
1.2.3.4/24describes the1.2.3.0/24network, not one host. It is not a recommended trusted range; replace it with the source range required by your clients.