Plaintext password in DMS MongoDB endpoint settings

Keep DMS MongoDB credentials out of templates and parameter defaults.

Description

Writing MongoDbSettings.Password directly in CloudFormation’s AWS::DMS::Endpoint, or in a parameter Default, leaves the MongoDB source endpoint’s credentials in the template and history.

Potential impact

Someone who can connect to the database and obtain the password may access source data within the migration account’s permissions.

Remediation

Supply the password securely without a default, or use DMS integration with Secrets Manager. Set NoEcho: true on a password parameter and keep its value out of logs and outputs. Replace an exposed password in MongoDB, update the DMS connection details, and test connectivity.

Examples

Supply the MongoDB source server and username. The original default is an illustrative password. In the revised template, securely supply the existing MongoDB account’s password as MasterMongoDBPassword. Endpoint configuration does not change the database account’s password.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    Default: "as@3djdkDjskjs73!!"
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    NoEcho: true
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

References