AWS AmazonCloudWatch: Use ArnLike for aws:SourceArn in account-level subscription filter policies
Summary
Two sample resource policies for account-level CloudWatch Logs subscription filters were updated to replace the StringLike condition operator with ArnLike for the aws:SourceArn condition key.
Security assessment
The surrounding text states the policy includes aws:SourceArn to help prevent cross-service impersonation; switching to ArnLike is the semantically correct operator for ARN matching and reduces the chance of overly broad or mismatched conditions. It is a hardening/correctness improvement in example policies, not a fix for a named vulnerability.
Evidence
+ "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" }
Diff
diff --git a/AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md b/AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md index 04fba4c9a..1456cb0c6 100644 --- a//AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md +++ b//AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md @@ -96 +96 @@ This policy includes a `aws:SourceArn` global condition context key to help prev - "StringLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } + "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } @@ -531 +531 @@ This policy includes a `aws:SourceArn` global condition context key to help prev - "StringLike": { + "ArnLike": {