Description
An API Gateway REST API cache cluster can reuse responses to repeated requests and reduce backend load. Absence of caching is not itself a vulnerability; first consider freshness and separation of user-specific data.
Potential impact
Repeatedly processing cacheable requests can increase backend load and response latency.
Remediation
When caching is appropriate, set CacheClusterEnabled: true and CachingEnabled: true for the intended methods. Choose cache keys and expiry to suit the responses.
Examples
The examples enable caching for GET responses. API and deployment resources and any required cache-key settings are omitted.
Before
yaml
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref MyDeployment
TracingEnabled: true
After
yaml
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref MyDeployment
TracingEnabled: true
CacheClusterEnabled: true
MethodSettings:
- ResourcePath: /*
HttpMethod: GET
CachingEnabled: true