AVD-AWS-0057 is detected when AWS IAM conditions are set in policy #6384
Malcolm-GetAHead
started this conversation in
False Detection
Replies: 2 comments 1 reply
-
What did you expect to happen differently in this case? |
Beta Was this translation helpful? Give feedback.
0 replies
-
In this case the policy is being applied to an EC2 instance, typically deployed as a disposable resource (autoscaling, etc) so attempting to use an ARN specific to the resource would be fairly difficult in a dynamic environment. By using conditions I'd expect the scanner to note that the scope is reduced from all EC2 instances to a specific subset and not flag this particular finding. Thanks! |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
AVD-AWS-0057
Description
When you configure conditions in an IAM policy that uses a wildcard in it's resource spec AVD-AWS-0057 is detected.
Reproduction Steps
Target
AWS
Scanner
Misconfiguration
Target OS
No response
Debug Output
Beta Was this translation helpful? Give feedback.
All reactions