logo

Database

Aws Not Protected With Waf

Description

Detects AWS CloudFront distributions that are not protected by AWS WAF (Web Application Firewall). CloudFront distributions without WAF protection are more vulnerable to web application attacks like SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats.

Weakness:

392 - Security controls bypass or absence - Firewall

Category: Functionality Abuse

Detection Strategy

    Scans all CloudFront distributions in the AWS account

    Reports a vulnerability when a CloudFront distribution's WebACLId field is empty or missing

    Each vulnerable distribution is reported individually with its specific ARN