Description
A security group allowing TCP port 80 from the entire internet permits external access to an HTTP service when a network path exists. HTTP itself does not encrypt traffic.
Potential impact
Sensitive requests and responses sent in plaintext can be exposed or modified in transit.
Remediation
Configure HTTPS for public services and remove unnecessary HTTP access. If HTTP is retained for redirection to HTTPS, the first HTTP request remains unencrypted.
Examples
The examples restrict HTTP access only; they do not enable HTTPS. Supply approved IPv4 and IPv6 ranges through the variables, and configure TLS separately on the application or load balancer.
Before
hcl
resource "aws_security_group" "example" {
name = "allow_tls"
description = "HTTP port open"
ingress {
description = "HTTP port open"
from_port = 80
to_port = 80
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
ipv6_cidr_blocks = ["::/0"]
}
}
After
hcl
resource "aws_security_group" "example" {
name = "allow_tls"
description = "sample"
ingress {
description = "sample"
from_port = 80
to_port = 80
protocol = "tcp"
cidr_blocks = var.approved_ipv4_cidrs
ipv6_cidr_blocks = var.approved_ipv6_cidrs
}
}