AWS AmazonCloudWatch: Fix aws:SourceArn condition operator to ArnLike in Firehose destination policy
Summary
Two IAM policy examples for the CloudWatch Logs to Firehose subscription destination were corrected to use the ArnLike condition operator instead of StringLike when matching the aws:SourceArn global condition key.
Security assessment
The aws:SourceArn condition key is an ARN, so ArnLike is the correct operator; StringLike on ARNs can produce imprecise matches. This tightens the resource-policy example that guards against cross-service confused-deputy access, but it is a documentation correctness fix rather than a response to a specific disclosed vulnerability.
Evidence
+ "ArnLike": {
Diff
diff --git a/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md b/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md index f6d980d01..dbf04fc35 100644 --- a//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md +++ b//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md @@ -88 +88 @@ This policy includes a `aws:SourceArn` global condition context key that specifi - "StringLike": { + "ArnLike": { @@ -121 +121 @@ The following is a sample output. Take note of the returned `Role.Arn` value, be - "StringLike": { + "ArnLike": {