CloudFront viewer protocol policy allows HTTP

Allowing HTTP in CloudFront can leave requests and responses between viewers and the CDN unencrypted.

Description

With viewer_protocol_policy: allow-all, CloudFront accepts both HTTP and HTTPS requests for content. HTTP traffic can be intercepted or modified in transit. This setting covers viewers’ connections to CloudFront; connections to the origin need separate protection.

Potential impact

  • Request parameters and response content sent over HTTP may be exposed or altered.
  • Unprotected credentials or session information sent over HTTP may be abused to access accounts.

Remediation

  • Set viewer_protocol_policy to https-only or redirect-to-https for each cache behavior.
  • The initial HTTP request before a redirect is unencrypted, so configure clients to use HTTPS from the start.
  • Check default and additional cache behaviors, certificates and TLS policy, and protect the origin connection as required.

Examples

These excerpts compare the viewer protocol for the default cache behavior. Other required settings, including cache policy configuration, are omitted.

Before

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique-test-distribution-id
    origins:
      - id: my-test-origin
        domain_name: www.example.com
    default_cache_behavior:
      target_origin_id: my-test-origin
      viewer_protocol_policy: allow-all

allow-all accepts HTTP requests. Offering HTTPS does not protect a request that uses HTTP.

After

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique-test-distribution-id
    origins:
      - id: my-test-origin
        domain_name: www.example.com
    default_cache_behavior:
      target_origin_id: my-test-origin
      viewer_protocol_policy: https-only

https-only rejects HTTP requests. Verify that legitimate clients connect using HTTPS.

References