Cloudfront without WAF
Web Application Firewall (WAF) should be setup in front of Cloudfront to mitigate various types of web attacks.
Remediation
Enable WAF. See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudfront_distribution#web_acl_id
Metadata
- Severity: informational
- Slug: cloudfront-without-waf