Skip to main content

PostgreSQL Server Does Not Restrict Access for Azure Services

Overview​

If access from Azure services is enabled, the server's firewall will accept connections from all Azure resources, including resources not in your subscription. This is usually not a desired configuration. Instead, set up firewall rules to allow access from specific network ranges or VNET rules to allow access from specific virtual networks.

Vendor​

Azure

Cloud Service​

PostgreSQL

CIS Azure v2.0.0 4.3.7

References​

https://docs.microsoft.com/en-us/azure/postgresql/concepts-firewall-rules, https://docs.microsoft.com/en-us/azure/postgresql/howto-manage-firewall-using-cli, https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-network-security#ns-1-establish-network-segmentation-boundaries, https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-network-security#ns-6-deploy-web-application-firewall

Severity​

3

Item Types​

Microsoft.DBforPostgreSQL.servers.databases