Description
CloudFront allows clients to retrieve content over plaintext HTTP when viewer_protocol_policy is allow-all.
Potential impact
HTTP requests and responses can be intercepted or modified on the network, exposing sensitive data.
Remediation
Set https-only or redirect-to-https for the default and additional cache behaviors. An initial HTTP request remains unencrypted before redirection, so clients should use HTTPS from the start.
Examples
The examples use https-only to reject HTTP requests. Supply the actual regional S3 domain through the bucket-domain variable; configure HTTPS to the origin separately.
Before
hcl
resource "aws_cloudfront_distribution" "example" {
origin {
domain_name = var.bucket_regional_domain_name
origin_id = "myS3Origin"
s3_origin_config {
origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
}
}
enabled = true
default_cache_behavior {
allowed_methods = ["DELETE", "GET", "HEAD", "OPTIONS", "PATCH", "POST", "PUT"]
cached_methods = ["GET", "HEAD"]
target_origin_id = "myS3Origin"
viewer_protocol_policy = "allow-all"
forwarded_values {
query_string = false
cookies {
forward = "none"
}
}
}
}
After
hcl
resource "aws_cloudfront_distribution" "example" {
origin {
domain_name = var.bucket_regional_domain_name
origin_id = "myS3Origin"
s3_origin_config {
origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
}
}
enabled = true
default_cache_behavior {
allowed_methods = ["DELETE", "GET", "HEAD", "OPTIONS", "PATCH", "POST", "PUT"]
cached_methods = ["GET", "HEAD"]
target_origin_id = "myS3Origin"
viewer_protocol_policy = "https-only"
forwarded_values {
query_string = false
cookies {
forward = "none"
}
}
}
}