Security group allows all ports from all addresses

Allow only required sources and service ports in security groups attached to ECS workloads.

Description

An ECS task or container-instance security group that permits all ports or all protocols from every IPv4 or IPv6 address can allow connections the service does not need. Actual external connectivity also depends on the task network mode, addresses, routes and listening services.

Potential impact

  • Reachable administrative or internal services can face unwanted connections and exploitation attempts.
  • Other workloads sharing the security group can inherit the same excessive access.

Remediation

  • Restrict sources, protocols and ports to actual communication requirements. Use supported security group references or approved private addresses for internal traffic.
  • Distinguish public listeners from internal task ports, and allow only required load-balancer and health-check traffic. Review both IPv4 and IPv6 rules.
  • Check every attached security group and the actual task network, then test that required traffic works and unwanted connections are blocked.

Examples

These examples compare TCP port ranges. Supply an actual VPC ID. They do not attach the group to an ECS service or task. All-address TCP 80 is appropriate only for an intentionally public HTTP service; configure required TLS protection separately.

Before

yaml
Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
Resources:
  EcsSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ECS Security Group
      VpcId: !Ref VpcId
  EcsSecurityGroupHTTPinbound:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref EcsSecurityGroup
      IpProtocol: tcp
      FromPort: 0
      ToPort: 65535
      CidrIp: 0.0.0.0/0

This permits TCP ports 0 through 65535 from every IPv4 address.

After

yaml
Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
Resources:
  EcsSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ECS Security Group
      VpcId: !Ref VpcId
  EcsSecurityGroupHTTPinbound:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref EcsSecurityGroup
      IpProtocol: tcp
      FromPort: 80
      ToPort: 80
      CidrIp: 0.0.0.0/0

This narrows the port to TCP 80, but still permits every IPv4 source. Also restrict the sources for an internal-only service.

References