AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Use ArnLike instead of StringLike in destination policy example

Service: AmazonCloudWatch · 2026-09-27 · Security-related medium

File: AmazonCloudWatch/latest/logs/CreateDestination-Account.md · Type: iam

Summary

Corrects the cross-account destination IAM policy example to use the ArnLike condition operator for the aws:SourceArn condition key, and fixes a minor grammar typo ('a Amazon' -> 'an Amazon').

Security assessment

The aws:SourceArn condition key in this cross-account delivery destination policy is now evaluated with ArnLike rather than StringLike. ArnLike applies ARN-aware matching semantics, so the wildcard/account portion cannot be matched as loosely as with a plain string operator, tightening which source log groups are authorized to write to the destination account — a concrete authorization-condition weakness fix. No CVE or advisory is referenced.

Evidence

+                "ArnLike": {

Diff

diff --git a/AmazonCloudWatch/latest/logs/CreateDestination-Account.md b/AmazonCloudWatch/latest/logs/CreateDestination-Account.md
index 135f876b4..2c3fdbc93 100644
--- a//AmazonCloudWatch/latest/logs/CreateDestination-Account.md
+++ b//AmazonCloudWatch/latest/logs/CreateDestination-Account.md
@@ -15 +15 @@ For this example, the log data recipient account has an AWS account ID of 999999
-This example creates a destination using a Amazon Kinesis Data Streams stream called RecipientStream, and a role that enables CloudWatch Logs to write data to it. 
+This example creates a destination using an Amazon Kinesis Data Streams stream called RecipientStream, and a role that enables CloudWatch Logs to write data to it. 
@@ -61 +61 @@ This policy includes a `aws:SourceArn` global condition context key that specifi
-                "StringLike": {
+                "ArnLike": {