Legacy DB security group allows all source addresses

Limit database access to required application and administrator sources.

Description

A DB security group that allows every source address can permit connections beyond operational needs. Actual reachability depends on the groups associated with the database, its public-access setting and network paths. Network connectivity does not grant data access; separate authentication and permissions still apply.

Potential impact

  • Unnecessary external connections and password-guessing attempts may increase.
  • Compromise of a vulnerable account or service can expose data or disrupt service.

Remediation

  • Remove unnecessary rules that allow all addresses, permitting only actual application and administrator sources.
  • Use VPC security groups for current RDS deployments and restrict sources and required database ports.
  • Verify that required connections still work and unwanted connections are blocked after the change.

Examples

These are historical DB Security Group CIDR comparisons. The EC2-Classic resource was removed in Terraform AWS provider 5.0; use VPC security groups for current environments. Do not declare both examples together.

Before

hcl
resource "aws_db_security_group" "db_sg" {
  name = "rds_sg"

  ingress {
    cidr = "0.0.0.0/0"
  }
}

This permits all IPv4 source addresses. The rule alone does not establish actual internet reachability of the database.

After

hcl
resource "aws_db_security_group" "db_sg" {
  name = "rds_sg"

  ingress {
    cidr = "10.0.0.0/8"
  }
}

This narrows the range to private 10.0.0.0/8. The example is still very broad; restrict it further to the actual approved client addresses.

References