aws-cloudfront-resource-tags-value-config

CloudFront distribution and function tag values are plaintext metadata.

awsmedium service: aws:cloudfront emits ContainsSecret

Where it sits

locationListTagsForResource.Tags.Items[].Value
location kindtag
data kindscredential sensitive_data
emits edgeContainsSecret
serviceCloudFront (aws:cloudfront)

Collection recipe

access moderead_api
operationListTagsForResource
response pathTags.Items[].Value
encodingstring
params{"Resource": "\u003cresource-arn\u003e"}

Required permissions

cloudfront:ListTagsForResource

References

move · open · esc close