Skip to content

H3-2022-0090

Public Access to Amazon RDS Snapshot

Category SECURITY_MISCONFIGURATION
Base Score 4.5

Description

An Amazon RDS Snapshot in your AWS account is publicly accessible, either to everyone or to any authenticated (cross-account) AWS user.

Impact

Attackers can deploy an RDS instance from this public RDS snapshot and search for sensitive data stored in the database.

References