HIGH
Source
CloudSploit
ID
open-elasticsearch

Open Elasticsearch

Determine if TCP port 9200 or 9300 for Elasticsearch is open to the public

While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as Elasticsearch should be restricted to known IP addresses.

Restrict TCP port 9200 or 9300 to known IP addresses