Description
A DB security group that allows every source address can permit connections beyond operational needs. Actual reachability depends on the groups associated with the database, its public-access setting and network paths. Network connectivity does not grant data access; separate authentication and permissions still apply.
Potential impact
- Unnecessary external connections and password-guessing attempts may increase.
- Compromise of a vulnerable account or service can expose data or disrupt service.
Remediation
- Remove unnecessary rules that allow all addresses, permitting only actual application and administrator sources.
- Use VPC security groups for current RDS deployments and restrict sources and required database ports.
- Verify that required connections still work and unwanted connections are blocked after the change.
Examples
These are historical DB Security Group CIDR comparisons. The EC2-Classic resource was removed in Terraform AWS provider 5.0; use VPC security groups for current environments. Do not declare both examples together.
Before
resource "aws_db_security_group" "db_sg" {
name = "rds_sg"
ingress {
cidr = "0.0.0.0/0"
}
}
This permits all IPv4 source addresses. The rule alone does not establish actual internet reachability of the database.
After
resource "aws_db_security_group" "db_sg" {
name = "rds_sg"
ingress {
cidr = "10.0.0.0/8"
}
}
This narrows the range to private 10.0.0.0/8. The example is still very broad; restrict it further to the actual approved client addresses.