aws-cloudformation-stack-parameter-value

Parameters without effective NoEcho protection are returned by DescribeStacks and frequently contain deployment credentials.

awscritical service: aws:cloudformation emits ContainsCredential

Where it sits

locationDescribeStacks.Stacks[].Parameters[].ParameterValue
location kindiac_template
data kindscredential password api_key access_key secret_key connection_string sensitive_data
emits edgeContainsCredential
serviceCloudFormation (aws:cloudformation)

Collection recipe

access moderead_api
operationDescribeStacks
response pathStacks[].Parameters[].ParameterValue
encodingstring
params{"StackName": "\u003cstack-name-or-id\u003e"}

Required permissions

cloudformation:DescribeStacks

References

move · open · esc close