aws-waf-inserted-header-values

WAF can insert static request or response headers; using real authentication values exposes them to origins or clients.

awscritical service: aws:waf emits ContainsCredential

Where it sits

locationGetWebACL.WebACL.Rules[].Action.{Allow,Captcha,Challenge}.CustomRequestHandling.InsertHeaders[].Value / WebACL.Rules[].Action.Block.CustomResponse.ResponseHeaders[].Value / WebACL.DefaultAction.Allow.CustomRequestHandling.InsertHeaders[].Value / WebACL.DefaultAction.Block.CustomResponse.ResponseHeaders[].Value
location kindconfig_field
data kindscredential api_key bearer_token sensitive_data
emits edgeContainsCredential
serviceWAF/Shield (aws:waf)

Collection recipe

access moderead_api
operationGetWebACL
response pathWebACL.Rules[].Action.{Allow,Captcha,Challenge}.CustomRequestHandling.InsertHeaders[].Value / WebACL.Rules[].Action.Block.CustomResponse.ResponseHeaders[].Value / WebACL.DefaultAction.Allow.CustomRequestHandling.InsertHeaders[].Value / WebACL.DefaultAction.Block.CustomResponse.ResponseHeaders[].Value
encodingjson
params{"Id": "\u003cweb-acl-id\u003e", "Name": "\u003cweb-acl-name\u003e", "Scope": "\u003cscope\u003e"}

Required permissions

wafv2:GetWebACL

References

move · open · esc close