HTTP port 80 is open to the internet

Use HTTPS for sensitive traffic to public web services.

Description

A security group allowing TCP port 80 from the entire internet permits external access to an HTTP service when a network path exists. HTTP itself does not encrypt traffic.

Potential impact

Sensitive requests and responses sent in plaintext can be exposed or modified in transit.

Remediation

Configure HTTPS for public services and remove unnecessary HTTP access. If HTTP is retained for redirection to HTTPS, the first HTTP request remains unencrypted.

Examples

The examples restrict HTTP access only; they do not enable HTTPS. Supply approved IPv4 and IPv6 ranges through the variables, and configure TLS separately on the application or load balancer.

Before

hcl
resource "aws_security_group" "example" {
  name        = "allow_tls"
  description = "HTTP port open"

  ingress {
    description = "HTTP port open"
    from_port   = 80
    to_port     = 80
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
    ipv6_cidr_blocks = ["::/0"]
  }
}

After

hcl
resource "aws_security_group" "example" {
  name        = "allow_tls"
  description = "sample"

  ingress {
    description = "sample"
    from_port   = 80
    to_port     = 80
    protocol    = "tcp"
    cidr_blocks = var.approved_ipv4_cidrs
    ipv6_cidr_blocks = var.approved_ipv6_cidrs
  }
}

References