AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Fix aws:SourceArn condition operator to ArnLike in Firehose destination policy

Service: AmazonCloudWatch · 2026-09-27 · Documentation medium

File: AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md · Type: iam

Summary

Two IAM policy examples for the CloudWatch Logs to Firehose subscription destination were corrected to use the ArnLike condition operator instead of StringLike when matching the aws:SourceArn global condition key.

Security assessment

The aws:SourceArn condition key is an ARN, so ArnLike is the correct operator; StringLike on ARNs can produce imprecise matches. This tightens the resource-policy example that guards against cross-service confused-deputy access, but it is a documentation correctness fix rather than a response to a specific disclosed vulnerability.

Evidence

+                "ArnLike": {

Diff

diff --git a/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md b/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md
index f6d980d01..dbf04fc35 100644
--- a//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md
+++ b//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination.md
@@ -88 +88 @@ This policy includes a `aws:SourceArn` global condition context key that specifi
-                "StringLike": {
+                "ArnLike": {
@@ -121 +121 @@ The following is a sample output. Take note of the returned `Role.Arn` value, be
-                        "StringLike": {
+                        "ArnLike": {