Description
If a service is designed to use CloudFront, a disabled distribution or missing origin configuration can prevent content from being delivered through the intended path. A CDN is not required for every external service, and its absence alone does not make a service vulnerable.
Enabling CloudFront does not by itself block direct access to the origin or application attacks. Review availability requirements together with the origin access policy.
Potential impact
- A distribution that is needed but unavailable can interrupt content delivery or concentrate load on the origin.
- Direct origin access can bypass access controls or filtering applied at CloudFront.
Remediation
- Determine whether the service needs a CDN, then configure
Enabled,Originsand cache behaviors for the required distribution. - Configure suitable origin access restrictions and HTTPS. Review viewer connections, authentication and any required WAF policies separately.
- Verify deployment status and the actual request path, and monitor errors and origin load.
Examples
These are distribution excerpts. A complete deployment also needs required settings such as a default cache behavior and a valid origin.
Before
Resources:
MyDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: false
DefaultRootObject: index.html
The distribution is disabled and has no origin.
After
Resources:
MyDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: true
DefaultRootObject: index.html
Origins:
- DomainName: www.example.com
Id: origin1
CustomOriginConfig:
HTTPPort: 80
HTTPSPort: 443
OriginProtocolPolicy: https-only
This enables the distribution and specifies a custom origin reached over HTTPS. The excerpt does not configure viewer HTTPS or restrictions on direct origin access.