AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Use ArnLike instead of StringLike in Firehose destination policies

Service: AmazonCloudWatch · 2026-09-27 · Security-related medium

File: AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md · Type: iam

Summary

Updates two IAM policy examples (destination policy and role trust/output policy) so the aws:SourceArn condition uses ArnLike instead of StringLike.

Security assessment

Both the destination access policy and the role policy for the Kinesis Firehose cross-account delivery example now evaluate aws:SourceArn with ArnLike, which enforces ARN-structured matching and avoids the overly permissive string matching that StringLike permits on the account/resource portions. This tightens the documented cross-account authorization boundary; no CVE or advisory is referenced.

Evidence

+                        "ArnLike": {

Diff

diff --git a/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md b/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md
index 325be7d83..b581987d6 100644
--- a//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md
+++ b//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md
@@ -88 +88 @@ This policy includes a `aws:SourceArn` global condition context key that specifi
-                "StringLike": {
+                "ArnLike": {
@@ -121 +121 @@ The following is a sample output. Take note of the returned `Role.Arn` value, be
-                        "StringLike": {
+                        "ArnLike": {