Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The firewall rule allows incoming traffic from any IP address (0.0.0.0/0) to port 3306, which is used by MySQL. This exposes your database to the public internet and makes it accessible to anyone.

Impact#

Attackers could attempt to connect directly to your MySQL database, potentially leading to unauthorized data access, data breaches, or database compromise. This significantly increases the risk of credential brute-forcing and exploitation of database vulnerabilities.