EC2-Classic DB security group allows all IPv4 addresses

A DB security group allowing all IPv4 sources can admit unnecessary connection attempts. Use supported VPC security groups to permit only required sources and database ports.

Description

A DB security-group range of 0.0.0.0/0 includes every IPv4 source. If the rule applies to an actual database connection path, unapproved sources can attempt connections. Allowing an address does not grant database authentication or data access permissions.

aws_db_security_group was for the retired EC2-Classic platform and was removed in Terraform AWS provider 5.0. Current RDS access control in a VPC uses VPC security groups and aws_db_instance.vpc_security_group_ids.

Potential impact

  • A database port reachable from broad sources can be exposed to unnecessary login attempts or attempts to exploit vulnerabilities.
  • Weak credentials or excessive database permissions can increase the risk of unauthorized data access or changes.

Remediation

  • Associate supported VPC security groups with RDS, allowing the required database port only from approved application security groups or administrative paths. Do not deploy the removed resource.
  • If using CIDRs, choose the smallest ranges needed for actual clients. Do not trust a range solely because it uses private addresses; identify the systems that can connect from it.
  • Review routing, group associations, and database authentication together. Changing resource types is more than a rule update: inspect creation, deletion, and dependencies in terraform plan, then test required connections after the change.

Examples

The first example uses a historical resource unsupported by the current provider. The second is a partial VPC configuration: define vpc_id and db_port, the actual database port, separately. Replace 10.0.0.0/25 with the required client range and associate the new group through the RDS instance's vpc_security_group_ids.

Before

hcl
resource "aws_db_security_group" "public_db_sg" {
  name = "rds_sg"

  ingress {
    cidr = "0.0.0.0/0"
  }
}

After

hcl
resource "aws_security_group" "db" {
  name   = "rds_sg"
  vpc_id = var.vpc_id
}

resource "aws_vpc_security_group_ingress_rule" "db_client" {
  security_group_id = aws_security_group.db.id
  cidr_ipv4         = "10.0.0.0/25"
  ip_protocol       = "tcp"
  from_port         = var.db_port
  to_port           = var.db_port
}

Explanation: The new configuration permits only the required TCP port from a specific IPv4 range. During migration, verify resource state and connection paths, and check that other groups or rules do not grant broader access.

References