Ce produit n'est pas pris en charge par le site Datadog que vous avez sélectionné. ().
Cette page n'est pas encore disponible en français, sa traduction est en cours. Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.
This vulnerability occurs when security groups allow inbound traffic to sensitive ports (such as SSH, RDP, database, or administrative service ports) from the entire internet (0.0.0.0/0 or /0). Exposing sensitive ports to the internet creates a significant security risk as it allows attackers from anywhere to attempt connections, potentially resulting in unauthorized access, data breaches, or service exploitation.
To remediate this issue, restrict access to sensitive ports by specifying narrower CIDR ranges or specific IP addresses in your security group rules. For example, instead of using cidr_blocks = ["0.0.0.0/0"], use specific IP ranges such as cidr_blocks = [aws_vpc.main.cidr_block] or cidr_blocks = ["10.0.0.0/16"] that only allow traffic from trusted networks.
Compliant Code Examples
resource"aws_security_group""negative1"{name="allow_tls1"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=2383to_port=2383protocol="tcp"cidr_blocks=[aws_vpc.main.cidr_block]}}resource"aws_security_group""negative2"{name="allow_tls2"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=2384to_port=2386protocol="tcp"cidr_blocks=["/0"]}}resource"aws_security_group""negative3"{name="allow_tls3"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=25to_port=2500protocol="tcp"cidr_blocks=["1.2.3.4/5"]}}resource"aws_security_group""negative4"{name="allow_tls4"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=25to_port=2500protocol="tcp"cidr_blocks=["1.2.3.4/5"]}}resource"aws_security_group""negative5"{name="allow_tls5"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=25to_port=2500protocol="udp"cidr_blocks=["1.2.3.4/5","0.0.0.0/12"]}}resource"aws_security_group""negative6"{name="allow_tls6"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=0to_port=0protocol="-1"cidr_blocks=["1.2.3.4/5","0.0.0.0/12"]}}
Non-Compliant Code Examples
resource"aws_security_group""positive1"{name="allow_tls1"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=2200to_port=2500protocol="-1"cidr_blocks=["0.0.0.0/0"]}}resource"aws_security_group""positive2"{name="allow_tls2"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=20to_port=60protocol="tcp"cidr_blocks=["/0"]}}resource"aws_security_group""positive3"{name="allow_tls3"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=5000to_port=6000protocol="-1"cidr_blocks=["0.0.0.0/0"]}}resource"aws_security_group""positive4"{name="allow_tls4"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=20to_port=22protocol="tcp"cidr_blocks=["/0"]}}resource"aws_security_group""positive5"{name="allow_tls5"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=445to_port=500protocol="udp"cidr_blocks=["1.1.1.1/1","0.0.0.0/0","2.2.3.4/12"]}}resource"aws_security_group""positive6"{name="allow_tls6"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=135to_port=170protocol="udp"cidr_blocks=["10.68.0.0","0.0.0.0/0"]}}resource"aws_security_group""positive7"{name="allow_tls7"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=2383to_port=2383protocol="udp"cidr_blocks=["/0","1.2.3.4/12"]}}resource"aws_security_group""positive8"{name="allow_tls8"description="Allow TLS inbound traffic"vpc_id=aws_vpc.main.idingress{description="TLS from VPC"from_port=0to_port=0protocol="-1"cidr_blocks=["/0"]}}
1
2
rulesets:- Terraform / AWS # Rules to enforce / AWS.
Request a personalized demo
Commencer avec Datadog
Ask AI
AI-generated responses may be inaccurate. Verify important info.