Description
When a CloudFront cache behavior uses ViewerProtocolPolicy set to allow-all, viewers can access content over HTTP.
Potential impact
Credentials or request content sent over HTTP can be exposed or altered along the network path.
Remediation
Apply https-only or redirect-to-https to each cache behavior. Send sensitive requests over HTTPS from the start instead of relying on a redirect.
Examples
The examples change the default cache behavior to reject HTTP. Check additional CacheBehaviors as well. HTTPS to the origin server is configured separately.
Before
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
DefaultCacheBehavior:
ViewerProtocolPolicy: allow-all
TargetOriginId: myOrigin
After
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
DefaultCacheBehavior:
ViewerProtocolPolicy: https-only
TargetOriginId: myOrigin