aws-waf-custom-response-body-content

Custom response bodies are publicly returned to matched clients and can accidentally publish sensitive text.

awscritical service: aws:waf emits ExposesCredential

Where it sits

locationGetWebACL.WebACL.CustomResponseBodies.<key>.Content
location kindconfig_field
data kindscredential api_key sensitive_data customer_data
emits edgeExposesCredential
serviceWAF/Shield (aws:waf)

Collection recipe

access moderead_api
operationGetWebACL
response pathWebACL.CustomResponseBodies.<key>.Content
encodingstring
params{"Id": "\u003cweb-acl-id\u003e", "Name": "\u003cweb-acl-name\u003e", "Scope": "\u003cscope\u003e"}

Required permissions

wafv2:GetWebACL

References

move · open · esc close