Description
Allowing TCP 80 from 0.0.0.0/0 or ::/0 in a security group permits that entire address range. Actual reachability also requires a public address or route and a listening service; the port number alone does not determine the application protocol.
Ordinary HTTP does not encrypt traffic. Public websites or HTTPS redirects may need port 80, but the initial HTTP request is already sent in plaintext before a redirect. Remove unnecessary public permissions for internal services.
Potential impact
- Reachable services can be targeted by external scans, vulnerability attacks, or request abuse.
- HTTP data can be exposed or modified in transit. Restricting access to private addresses does not provide encryption.
Remediation
- For internal services, permit only necessary client CIDRs or appropriate security groups and review permissions in other attached groups.
- Send sensitive requests directly over HTTPS and validate certificates. Review HTTP redirects, HSTS, and secure cookie policies for public services.
- Remove unnecessary TCP 80 rules and verify service authentication, permissions, and legitimate connectivity.
Examples
myVPC must refer to the actual VPC. Service and routing configuration are omitted.
Before
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow http to client host
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
This inbound rule allows TCP 80 from every IPv4 address.
After
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow http to client host
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 192.168.0.0/16
This rule narrows its permission to 192.168.0.0/16. Do not trust this entire broad private range; restrict it to the actual client addresses. Configure transport security separately.