AWS Security ChangesHomeSearch

AWS appstream2: Add confused deputy prevention conditions to S3 bucket policies

Service: appstream2 · 2026-09-30 · Security-related high

File: appstream2/latest/developerguide/s3-permissions.md · Type: iam

Summary

Updates example S3 bucket policies to add aws:SourceAccount conditions for confused deputy prevention and splits out a separate statement granting appstream.amazonaws.com GetObject access to application icons, noting icons don't support confused deputy prevention.

Security assessment

The change adds aws:SourceAccount condition keys to the cross-service S3 bucket policy statements, which is the documented mechanism for cross-service confused deputy prevention, tightening IAM trust so only the intended account's service calls are honored.

Evidence

                "aws:SourceAccount": "111122223333"

Diff

diff --git a/appstream2/latest/developerguide/s3-permissions.md b/appstream2/latest/developerguide/s3-permissions.md
index 1db8fa3..1910de1 100644
--- a//appstream2/latest/developerguide/s3-permissions.md
+++ b//appstream2/latest/developerguide/s3-permissions.md
@@ -15,4 +15 @@ This section presents examples of typical use cases for bucket policies. These s
-JSON
-    
-
-****
+###### Note
@@ -19,0 +17 @@ JSON
+WorkSpaces Applications doesn't support confused deputy prevention for application icons, so the statement that grants access to the application icon object can't include a condition. For more information, see [Example: WorkSpaces Applications Application Amazon S3 bucket policy cross-service confused deputy prevention](./example-s3-bucket.html).
@@ -26 +24 @@ JSON
-           "Sid": "AllowAppStream2.0ToRetrieveObjects", 
+           "Sid": "AllowAppStream20ToRetrieveObjects",
@@ -35 +32,0 @@ JSON
-               "arn:aws:s3:::bucket/Application icon object",
@@ -37 +34,15 @@ JSON
-             ]         
+             ],
+            "Condition": {
+              "StringEquals": {
+                "aws:SourceAccount": "111122223333"
+              }
+            }
+          },
+          {
+           "Sid": "AllowRetrievalPermissionsToS3AppIconsForAppStream",
+           "Effect": "Allow",
+           "Principal": {
+              "Service": ["appstream.amazonaws.com"]
+            },
+            "Action": ["s3:GetObject"],
+            "Resource": "arn:aws:s3:::bucket/Application icon object"
@@ -49,6 +58,0 @@ If you are using an WorkSpaces Applications app block, then WorkSpaces Applicati
-JSON
-    
-
-****
-    
-    
@@ -60 +64 @@ JSON
-          "Sid": "AllowAppStream2.0ToPutAndRetrieveObjects",
+          "Sid": "AllowAppStream20ToPutAndRetrieveObjects",
@@ -77 +80,0 @@ JSON
-            "arn:aws:s3:::bucket/Application icon object",
@@ -78,0 +82,13 @@ JSON
+          ],
+          "Condition": {
+            "StringEquals": {
+              "aws:SourceAccount": "111122223333"
+            }
+          }
+        },
+        {
+          "Sid": "AllowRetrievalPermissionsToS3AppIconsForAppStream",
+          "Effect": "Allow",
+          "Principal": {
+            "Service": [
+              "appstream.amazonaws.com"
@@ -79,0 +96,5 @@ JSON
+          },
+          "Action": [
+            "s3:GetObject"
+          ],
+          "Resource": "arn:aws:s3:::bucket/Application icon object"