AppSync GraphQL API query depth limit high

firetail:aws-appsync-query-depth-limit-high

Type:

CSPM

Rule Severity:

Medium

The AppSync GraphQL API has a high query depth limit.

A high query depth limit increases the risk of performance bottlenecks, leading to slow responses or potential outages. Attackers or even legitimate users could unintentionally issue complex, deeply nested queries that overload the system, consuming excessive resources and reducing the overall availability and responsiveness of the API.

Remediation

Set a query depth limit on the AppSync GraphQL API to less than 10.

Example Attack Scenario

How to Identify with Example Scenario

How to Resolve with Example Scenario

How to Identify with Example Scenario

Find the text in bold to identify issues such as these in API specifications

How to Resolve with Example Scenario

Modify the text in bold to resolve issues such as these in API specifications
References:

More findings

All Findings