Amazon MQ broker has public access enabled

Review the need for public Amazon MQ access, and connect internal-only brokers through private paths and restricted security groups.

Description

Amazon MQ's PubliclyAccessible: true enables public access for connections from outside the VPC hosting the broker. Actual connectivity also depends on security groups and network settings; public access does not remove authentication or message permissions.

Use approved private connectivity when messaging is needed only between internal systems.

Potential impact

  • A reachable broker can face unwanted login and exploitation attempts.
  • Authentication or authorization weaknesses can combine with exposure to cause message disclosure, modification or service interruption.

Remediation

  • Set PubliclyAccessible: false for an internal-only broker and prepare private client connectivity and required security group rules.
  • Changing this property through CloudFormation requires broker replacement. Plan the new broker name, continuity of message processing, client cutover and downtime.
  • Even when public access is required, minimize sources and service ports and verify authentication, message permissions and TLS. Test required connections and message operations after cutover.

Examples

These are alternatives for a new single-instance ActiveMQ broker. Supply a supported instance type, a subnet and security group in the same VPC, and a username. Store a valid broker password under the password key in Secrets Manager and grant the deployment principal permission to read it. Omitting the engine version uses the service default. These examples do not guarantee an uninterrupted update of an existing broker.

Before

yaml
Parameters:
  BrokerName:
    Type: String
  HostInstanceType:
    Type: String
  SubnetId:
    Type: AWS::EC2::Subnet::Id
  SecurityGroupId:
    Type: AWS::EC2::SecurityGroup::Id
  BrokerUsername:
    Type: String
  BrokerPasswordSecretArn:
    Type: String
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      BrokerName: !Ref BrokerName
      DeploymentMode: SINGLE_INSTANCE
      EngineType: ACTIVEMQ
      AutoMinorVersionUpgrade: true
      HostInstanceType: !Ref HostInstanceType
      SubnetIds:
        - !Ref SubnetId
      SecurityGroups:
        - !Ref SecurityGroupId
      Users:
        - Username: !Ref BrokerUsername
          Password: !Sub '{{resolve:secretsmanager:${BrokerPasswordSecretArn}:SecretString:password}}'
      PubliclyAccessible: true

This enables public access. Also inspect the supplied network and security group to determine actual allowed connections.

After

yaml
Parameters:
  BrokerName:
    Type: String
  HostInstanceType:
    Type: String
  SubnetId:
    Type: AWS::EC2::Subnet::Id
  SecurityGroupId:
    Type: AWS::EC2::SecurityGroup::Id
  BrokerUsername:
    Type: String
  BrokerPasswordSecretArn:
    Type: String
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      BrokerName: !Ref BrokerName
      DeploymentMode: SINGLE_INSTANCE
      EngineType: ACTIVEMQ
      AutoMinorVersionUpgrade: true
      HostInstanceType: !Ref HostInstanceType
      SubnetIds:
        - !Ref SubnetId
      SecurityGroups:
        - !Ref SecurityGroupId
      Users:
        - Username: !Ref BrokerUsername
          Password: !Sub '{{resolve:secretsmanager:${BrokerPasswordSecretArn}:SecretString:password}}'
      PubliclyAccessible: false

This disables public access. Verify that clients can reach the new broker privately and perform required message operations.

References