AWS iot-device-defender: Correct API reference URLs in confused deputy prevention guide
Summary
Fixed URLs for UpdateAccountAuditConfiguration, CreateMitigationAction, and CreateSecurityProfile APIs.
Security assessment
Changes fix URL formatting in authorization context without altering security guidance.
Evidence
+ * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com/iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:.
Diff
diff --git a/iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md b/iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md index 96f68006c..a8c35ea76 100644 --- a//iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md +++ b//iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md @@ -13 +13 @@ There are three resources AWS IoT Device Defender acesses from you that can be e - * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com//iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:`. + * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com/iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:`. @@ -15 +15 @@ There are three resources AWS IoT Device Defender acesses from you that can be e - * For resources passed in [CreateMitigationAction](https://docs.aws.amazon.com//iot/latest/apireference/API_CreateMitigationAction.html) API (The RoleArn attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:mitigationaction/`mitigationActionName``. + * For resources passed in [CreateMitigationAction](https://docs.aws.amazon.com/iot/latest/apireference/API_CreateMitigationAction.html) API (The RoleArn attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:mitigationaction/`mitigationActionName``. @@ -17 +17 @@ There are three resources AWS IoT Device Defender acesses from you that can be e - * For resources passed in [CreateSecurityProfile](https://docs.aws.amazon.com//iot/latest/apireference/API_CreateSecurityProfile.html) API (the alertTargets attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:securityprofile/`securityprofileName``. + * For resources passed in [CreateSecurityProfile](https://docs.aws.amazon.com/iot/latest/apireference/API_CreateSecurityProfile.html) API (the alertTargets attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:securityprofile/`securityprofileName``.