Description
Setting ipRanges.cidrIp to 0.0.0.0/0 in a Crossplane SecurityGroup allows every IPv4 source for the specified ports and protocols. Actual internet reachability also depends on the attached resources, public addressing and routing. A security group does not itself create a public interface or remove database authentication.
Limit database access to the applications and approved management paths that need it. A broad rule in a Composition can be reused across multiple services.
Potential impact
- If a resource is reachable from the internet, external clients can attempt connections and logins on the permitted ports.
- Misused credentials or an exploited service vulnerability could lead to data disclosure or modification.
Remediation
- Replace
0.0.0.0/0with narrow CIDRs for the clients that need access, or appropriate source security groups. Do not treat an entire private range as trusted. - Allow only the required ports and protocols, and review other attached security groups and actual network paths.
- Correct Composition defaults too, then verify that approved connections succeed and unwanted external connections are blocked.
Examples
These partial examples show inbound security group rules. Their resource names differ, so adding the second definition alone does not change the existing rule.
Before
apiVersion: ec2.aws.crossplane.io/v1beta1
kind: SecurityGroup
metadata:
name: ec2-rule2
spec:
forProvider:
region: us-east-1
ingress:
- fromPort: 5432
toPort: 5432
ipProtocol: tcp
ipRanges:
- cidrIp: 0.0.0.0/0
description: Everywhere
Every IPv4 source is allowed on TCP port 5432. Actual database exposure depends on the attached resources and network configuration.
After
apiVersion: ec2.aws.crossplane.io/v1beta1
kind: SecurityGroup
metadata:
name: ec2-rule1
spec:
forProvider:
region: us-east-1
ingress:
- fromPort: 5432
toPort: 5432
ipProtocol: tcp
ipRanges:
- cidrIp: 10.0.0.0/8
description: Internal network
The source range is reduced to 10.0.0.0/8. This private range is still very broad; restrict it further to the clients that need access.