TF 0491 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

Compute instance requests an IP reservation from a public pool

Property Value
Language terraform
Severity critical
Service compute
Provider Oracle
Vulnerability Type misconfiguration

Description

A compute instance is configured to reserve an IP address from a public IP pool, making it accessible from the internet. This exposure increases the risk of unauthorized access if proper security controls are not enforced.

Impact

If exploited, attackers could connect directly to the compute instance from outside the organization's network, potentially leading to data breaches, service disruption, or unauthorized control over the instance.

Resolution

Reconsider the use of an public IP