aws-waf-custom-response-body-content
Custom response bodies are publicly returned to matched clients and can accidentally publish sensitive text.
Where it sits
| location | GetWebACL.WebACL.CustomResponseBodies.<key>.Content |
| location kind | config_field |
| data kinds | credential api_key sensitive_data customer_data |
| emits edge | ExposesCredential |
| service | WAF/Shield (aws:waf) |
Collection recipe
| access mode | read_api |
| operation | GetWebACL |
| response path | WebACL.CustomResponseBodies.<key>.Content |
| encoding | string |
| params | {"Id": "\u003cweb-acl-id\u003e", "Name": "\u003cweb-acl-name\u003e", "Scope": "\u003cscope\u003e"} |
Required permissions
References