TF 0498 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

A database resource is marked as publicly accessible.

Property Value
Language terraform
Severity critical
Service rdb
Provider Nifcloud
Vulnerability Type omission

Description

The database resource is configured to allow public access, exposing it to the internet without network restrictions. This setting makes the database reachable from any external source.

Impact

If exploited, attackers could connect to the database over the internet, potentially leading to unauthorized data access, data theft, or manipulation. This exposure significantly increases the risk of data breaches and compromises the security of sensitive information managed by the application.

Resolution

Set the database to not be publicly accessible