Description
A NIFCLOUD NAS security group with cidr_ip set to 0.0.0.0/0 includes every IPv4 address in its allowed range. If the NAS is reachable from those addresses and file-share permissions allow it, unintended file reads or changes may follow.
The impact depends on network paths, the NAS security-group association and file-share permissions. When multiple services share a NAS, file modification or deletion can affect them together.
Potential impact
- Excessive network allowances and file permissions can enable data disclosure or modification.
- Damage to or deletion of shared files can interrupt multiple applications.
Remediation
Remove unnecessary 0.0.0.0/0 allowances and restrict cidr_ip to servers that need the NAS and approved management addresses. Provide private connectivity and limit file-share read/write permissions to required tasks. Verify that necessary mounts and file operations succeed and unapproved clients cannot access the share.
Examples
These examples restrict access on the same NAS security group. Replace 10.0.0.0/16 with the actual client range and provide connectivity from that network to the NAS. NAS association and file-share settings are omitted.
Before
resource "nifcloud_nas_security_group" "shared_storage" {
group_name = "nasgroup001"
availability_zone = "east-11"
rule {
cidr_ip = "0.0.0.0/0"
}
}
The allowed range includes every IPv4 address. Review actual network access and file permissions on the associated NAS.
After
resource "nifcloud_nas_security_group" "shared_storage" {
group_name = "nasgroup001"
availability_zone = "east-11"
rule {
cidr_ip = "10.0.0.0/16"
}
}
Sources are limited to a private range. Check whether every client in that range needs access and whether file permissions are appropriate.