Skip to content

ReferenceThe 22 checks

Exposed databases

Security checkexposed-databases

What it reads

Whether MongoDB, Redis, PostgreSQL or MySQL listen on a public address or are published by Docker, and whether the firewall on this server blocks them.

Does it need root?

It needs root for part of what it reads. Reading the firewall rules needs root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • No database is open to the internet

What it can find

CriticalReported as likely

database is open to the internet on port port

Anyone can connect and read or wipe the data. A cloud firewall outside the server cannot be seen from here, so this is likely, not confirmed.

Fix
bind the port to 127.0.0.1 in docker-compose.yml, then
docker compose up -d service

The fix changes with how the server is set up:

If the container was started with docker run
recreate the container with -p 127.0.0.1:port:port in place of -p port:port
Redis installed on the server
set bind 127.0.0.1 ::1 in /etc/redis/redis.conf, then sudo systemctl restart redis-server
MongoDB installed on the server
set bindIp: 127.0.0.1 under net: in /etc/mongod.conf, then sudo systemctl restart mongod
PostgreSQL installed on the server
set listen_addresses = 'localhost' in postgresql.conf, then sudo systemctl restart postgresql
MySQL installed on the server
set bind-address = 127.0.0.1 in /etc/mysql/mysql.conf.d/mysqld.cnf, then sudo systemctl restart mysql