CloudFront allows HTTP viewer connections

Require HTTPS for viewer connections to CloudFront.

Description

When a CloudFront cache behavior uses ViewerProtocolPolicy set to allow-all, viewers can access content over HTTP.

Potential impact

Credentials or request content sent over HTTP can be exposed or altered along the network path.

Remediation

Apply https-only or redirect-to-https to each cache behavior. Send sensitive requests over HTTPS from the start instead of relying on a redirect.

Examples

The examples change the default cache behavior to reject HTTP. Check additional CacheBehaviors as well. HTTPS to the origin server is configured separately.

Before

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        DefaultCacheBehavior:
          ViewerProtocolPolicy: allow-all
          TargetOriginId: myOrigin

After

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        DefaultCacheBehavior:
          ViewerProtocolPolicy: https-only
          TargetOriginId: myOrigin

References