AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Use ArnLike for aws:SourceArn in account-level subscription filter policies

Service: AmazonCloudWatch · 2026-09-27 · Documentation medium

File: AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md · Type: iam

Summary

Two sample resource policies for account-level CloudWatch Logs subscription filters were updated to replace the StringLike condition operator with ArnLike for the aws:SourceArn condition key.

Security assessment

The surrounding text states the policy includes aws:SourceArn to help prevent cross-service impersonation; switching to ArnLike is the semantically correct operator for ARN matching and reduces the chance of overly broad or mismatched conditions. It is a hardening/correctness improvement in example policies, not a fix for a named vulnerability.

Evidence

+            "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 

Diff

diff --git a/AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md b/AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md
index 04fba4c9a..1456cb0c6 100644
--- a//AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md
+++ b//AmazonCloudWatch/latest/logs/SubscriptionFilters-AccountLevel.md
@@ -96 +96 @@ This policy includes a `aws:SourceArn` global condition context key to help prev
-            "StringLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 
+            "ArnLike": { "aws:SourceArn": "arn:aws:logs:region:123456789012:*" } 
@@ -531 +531 @@ This policy includes a `aws:SourceArn` global condition context key to help prev
-             "StringLike": { 
+             "ArnLike": {