🚀 Join our AI Wargame at Black Hat Asia and our Workshop + Wargame at NDC Sydney .


Cloudfront Insufficient Logging

Insufficient logging makes it difficult to detect suspicious attempts, potentially allowing security intrusions to go undetected for an extended period.

Remediation

Enable logging for CloudFront. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudfront_distribution#logging_config

Metadata

  • Severity: informational
  • Slug: cloudfront-insufficient-logging

CWEs

  • 778: Insufficient Logging

OWASP

  • A09:2021: Security Logging and Monitoring Failures

Available Labs

Open Aws labs in SecDim Play for this vulnerability.

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more