This product is not supported for your selected Datadog site. ().

Metadata

Id: a0b846e8-815f-4f15-b660-bc4ab9fa1e1a

Cloud Provider: Nifcloud

Platform: Terraform

Severity: High

Category: Networking and Firewall

Learn More

Description

A nifcloud_db_security_group ingress security group rule allows traffic from /0. The rule parses rule[].cidr_ip, splitting on / and converting the suffix to a number; it flags when that numeric mask is less than 1, indicating a CIDR of /0. This represents an overly permissive cidr range that allows traffic from any IP address.

Compliant Code Examples

resource "nifcloud_db_security_group" "negative" {
  group_name        = "example"
  availability_zone = "east-11"
  rule {
    cidr_ip = "10.0.0.0/16"
  }
}

Non-Compliant Code Examples

resource "nifcloud_db_security_group" "positive" {
  group_name        = "example"
  availability_zone = "east-11"
  rule {
    cidr_ip = "0.0.0.0/0"
  }
}