AWS Security ChangesHomeSearch

AWS iot-device-defender: Correct API reference URLs in confused deputy prevention guide

Service: iot-device-defender · 2026-08-19 · Documentation low

File: iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md · Type: authz

Summary

Fixed URLs for UpdateAccountAuditConfiguration, CreateMitigationAction, and CreateSecurityProfile APIs.

Security assessment

Changes fix URL formatting in authorization context without altering security guidance.

Evidence

+  * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com/iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:.

Diff

diff --git a/iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md b/iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md
index 96f68006c..a8c35ea76 100644
--- a//iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md
+++ b//iot-device-defender/latest/devguide/dd-cross-service-confused-deputy-prevention.md
@@ -13 +13 @@ There are three resources AWS IoT Device Defender acesses from you that can be e
-  * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com//iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:`.
+  * For resources passed in [UpdateAccountAuditConfiguration](https://docs.aws.amazon.com/iot/latest/apireference/API_UpdateAccountAuditConfiguration.html) API (RoleArn and notificationTarget RoleArn attributes) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:`.
@@ -15 +15 @@ There are three resources AWS IoT Device Defender acesses from you that can be e
-  * For resources passed in [CreateMitigationAction](https://docs.aws.amazon.com//iot/latest/apireference/API_CreateMitigationAction.html) API (The RoleArn attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:mitigationaction/`mitigationActionName``.
+  * For resources passed in [CreateMitigationAction](https://docs.aws.amazon.com/iot/latest/apireference/API_CreateMitigationAction.html) API (The RoleArn attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:mitigationaction/`mitigationActionName``.
@@ -17 +17 @@ There are three resources AWS IoT Device Defender acesses from you that can be e
-  * For resources passed in [CreateSecurityProfile](https://docs.aws.amazon.com//iot/latest/apireference/API_CreateSecurityProfile.html) API (the alertTargets attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:securityprofile/`securityprofileName``.
+  * For resources passed in [CreateSecurityProfile](https://docs.aws.amazon.com/iot/latest/apireference/API_CreateSecurityProfile.html) API (the alertTargets attribute) you should scope down the resource policy by using `aws:SourceArn` as `arn:`arnPartition`:iot:`region`:`accountId`:securityprofile/`securityprofileName``.