Skip to main content

πŸ’Ό [CloudFront.12] CloudFront distributions should not point to non-existent S3 origins

  • Contextual name: πŸ’Ό [CloudFront.12] CloudFront distributions should not point to non-existent S3 origins

  • ID: /frameworks/aws-fsbp-v1.0.0/cloudfront/12

  • Located in: πŸ’Ό CloudFront

Description​

When a CloudFront distribution in your account is configured to point to a non-existent bucket, a malicious third party can create the referenced bucket and serve their own content through your distribution. We recommend checking all origins regardless of routing behavior to ensure that your distributions are pointing to appropriate origins.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2(2) Baseline Configuration _ Automation Support for Accuracy and Currency13
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 2.2.6 System security parameters are configured to prevent misuse.1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags