Security group rule allows all IPv4 addresses

A security group rule allowing every IPv4 address can permit unwanted connection attempts to reachable resources.

Description

Setting ipRanges.cidrIp to 0.0.0.0/0 in a Crossplane SecurityGroup allows every IPv4 source for the specified ports and protocols. Actual internet reachability also depends on the attached resources, public addressing and routing. A security group does not itself create a public interface or remove database authentication.

Limit database access to the applications and approved management paths that need it. A broad rule in a Composition can be reused across multiple services.

Potential impact

  • If a resource is reachable from the internet, external clients can attempt connections and logins on the permitted ports.
  • Misused credentials or an exploited service vulnerability could lead to data disclosure or modification.

Remediation

  • Replace 0.0.0.0/0 with narrow CIDRs for the clients that need access, or appropriate source security groups. Do not treat an entire private range as trusted.
  • Allow only the required ports and protocols, and review other attached security groups and actual network paths.
  • Correct Composition defaults too, then verify that approved connections succeed and unwanted external connections are blocked.

Examples

These partial examples show inbound security group rules. Their resource names differ, so adding the second definition alone does not change the existing rule.

Before

yaml
apiVersion: ec2.aws.crossplane.io/v1beta1
kind: SecurityGroup
metadata:
  name: ec2-rule2
spec:
  forProvider:
    region: us-east-1
    ingress:
      - fromPort: 5432
        toPort: 5432
        ipProtocol: tcp
        ipRanges:
          - cidrIp: 0.0.0.0/0
            description: Everywhere

Every IPv4 source is allowed on TCP port 5432. Actual database exposure depends on the attached resources and network configuration.

After

yaml
apiVersion: ec2.aws.crossplane.io/v1beta1
kind: SecurityGroup
metadata:
  name: ec2-rule1
spec:
  forProvider:
    region: us-east-1
    ingress:
      - fromPort: 5432
        toPort: 5432
        ipProtocol: tcp
        ipRanges:
          - cidrIp: 10.0.0.0/8
            description: Internal network

The source range is reduced to 10.0.0.0/8. This private range is still very broad; restrict it further to the clients that need access.

References