More Info:

Ensure S3 Alias Records are not vulnerable

Risk Level

Critical

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

  1. Sign in to the AWS Management Console.
  2. Navigate to the Route 53 service.
  3. Select Hosted zones from the navigation pane.
  4. Identify vulnerable DNS Alias records:
    • Look for Alias records that point to S3 buckets with website hosting enabled.
  5. Review Alias record settings:
    • Click on each vulnerable record.
    • Review the Alias Target to ensure it points to a secure S3 bucket.
  6. Secure the S3 bucket:
    • If the S3 bucket is configured insecurely (e.g., publicly accessible), modify its permissions to restrict access as necessary.
  7. Repeat for other vulnerable records:
    • Repeat the above steps for all vulnerable DNS Alias records.