aws-cloudfront-key-value-store-value

CloudFront KeyValueStore values are application-controlled strings and can be misused as a secret store.

awscritical service: aws:cloudfront emits CanReadData

Where it sits

locationcloudfront-keyvaluestore:GetKey.Value
location kinddata_record
data kindscredential password api_key bearer_token sensitive_data
emits edgeCanReadData
serviceCloudFront (aws:cloudfront)

Collection recipe

access moderead_api
operationGetKey
response pathValue
encodingstring
params{"Key": "\u003ckey\u003e", "KvsARN": "\u003ckey-value-store-arn\u003e"}

Required permissions

cloudfront-keyvaluestore:GetKey

References

move · open · esc close