Description
An ECS task or container-instance security group that permits all ports or all protocols from every IPv4 or IPv6 address can allow connections the service does not need. Actual external connectivity also depends on the task network mode, addresses, routes and listening services.
Potential impact
- Reachable administrative or internal services can face unwanted connections and exploitation attempts.
- Other workloads sharing the security group can inherit the same excessive access.
Remediation
- Restrict sources, protocols and ports to actual communication requirements. Use supported security group references or approved private addresses for internal traffic.
- Distinguish public listeners from internal task ports, and allow only required load-balancer and health-check traffic. Review both IPv4 and IPv6 rules.
- Check every attached security group and the actual task network, then test that required traffic works and unwanted connections are blocked.
Examples
These examples compare TCP port ranges. Supply an actual VPC ID. They do not attach the group to an ECS service or task. All-address TCP 80 is appropriate only for an intentionally public HTTP service; configure required TLS protection separately.
Before
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
Resources:
EcsSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ECS Security Group
VpcId: !Ref VpcId
EcsSecurityGroupHTTPinbound:
Type: AWS::EC2::SecurityGroupIngress
Properties:
GroupId: !Ref EcsSecurityGroup
IpProtocol: tcp
FromPort: 0
ToPort: 65535
CidrIp: 0.0.0.0/0
This permits TCP ports 0 through 65535 from every IPv4 address.
After
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
Resources:
EcsSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ECS Security Group
VpcId: !Ref VpcId
EcsSecurityGroupHTTPinbound:
Type: AWS::EC2::SecurityGroupIngress
Properties:
GroupId: !Ref EcsSecurityGroup
IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
This narrows the port to TCP 80, but still permits every IPv4 source. Also restrict the sources for an internal-only service.