Access to Cloud Service Information

NOTE
ACLs for the Cloud Service Information and the OSGi settings required to secure your instance are automated as part of the Production Ready Mode. While this means that you do not need to change the configuration manually, it is still recommended that you review them before you go live with your deployment.

When you integrate your AEM instance with the Adobe Experience Cloud, you use Cloud Service configurations. Information about these configurations, together with any statistics collected are stored in the repository. Adobe recommends that, if you are using this functionality, you review whether the default security on this information matches your requirements.

The webservicesupport module writes statistics and configuration information under:

/etc/cloudservices

With the default permissions:

  • Author environment: read for contributors

  • Publish environment: read for everyone

Protect against Cross-Site Request Forgery Attacks

For more information on the security mechanisms AEM employs to mitigate CSRF attacks, see the Sling Referrer Filter section of the Security Checklist and the CSRF Protection Framework documentation.

Experience Manager