aws-cloudhsm-hsm-user-password-command-input

CloudHSM user passwords are supplied to the cluster client and can leak through shell history or automation even though they are not AWS control-plane fields.

awscritical service: aws:cloudhsm emits ContainsCredential

Where it sits

locationCloudHSM CLI user create/change-password password input
location kindsecret_value
data kindspassword credential
emits edgeContainsCredential
serviceCloudHSM (aws:cloudhsm)

Collection recipe

access modewrite_only_input
operationCloudHSM CLI user create / user change-password
response pathrequest.password
encodingstring
params{"ClusterId": "\u003ccluster-id\u003e", "UserName": "\u003chsm-user\u003e"}

References

move · open · esc close