AWS AmazonCloudWatch: Use ArnLike instead of StringLike in destination policy example
Summary
Corrects the cross-account destination IAM policy example to use the ArnLike condition operator for the aws:SourceArn condition key, and fixes a minor grammar typo ('a Amazon' -> 'an Amazon').
Security assessment
The aws:SourceArn condition key in this cross-account delivery destination policy is now evaluated with ArnLike rather than StringLike. ArnLike applies ARN-aware matching semantics, so the wildcard/account portion cannot be matched as loosely as with a plain string operator, tightening which source log groups are authorized to write to the destination account — a concrete authorization-condition weakness fix. No CVE or advisory is referenced.
Evidence
+ "ArnLike": {
Diff
diff --git a/AmazonCloudWatch/latest/logs/CreateDestination-Account.md b/AmazonCloudWatch/latest/logs/CreateDestination-Account.md index 135f876b4..2c3fdbc93 100644 --- a//AmazonCloudWatch/latest/logs/CreateDestination-Account.md +++ b//AmazonCloudWatch/latest/logs/CreateDestination-Account.md @@ -15 +15 @@ For this example, the log data recipient account has an AWS account ID of 999999 -This example creates a destination using a Amazon Kinesis Data Streams stream called RecipientStream, and a role that enables CloudWatch Logs to write data to it. +This example creates a destination using an Amazon Kinesis Data Streams stream called RecipientStream, and a role that enables CloudWatch Logs to write data to it. @@ -61 +61 @@ This policy includes a `aws:SourceArn` global condition context key that specifi - "StringLike": { + "ArnLike": {