Description
Writing MongoDbSettings.Password directly in CloudFormation’s AWS::DMS::Endpoint, or in a parameter Default, leaves the MongoDB source endpoint’s credentials in the template and history.
Potential impact
Someone who can connect to the database and obtain the password may access source data within the migration account’s permissions.
Remediation
Supply the password securely without a default, or use DMS integration with Secrets Manager. Set NoEcho: true on a password parameter and keep its value out of logs and outputs. Replace an exposed password in MongoDB, update the DMS connection details, and test connectivity.
Examples
Supply the MongoDB source server and username. The original default is an illustrative password. In the revised template, securely supply the existing MongoDB account’s password as MasterMongoDBPassword. Endpoint configuration does not change the database account’s password.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
Default: "as@3djdkDjskjs73!!"
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
NoEcho: true
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername