aws-cloudwatch-metric-dimension-values

Custom metric dimension values are plaintext and may accidentally encode usernames, account identifiers, or tokens.

awshigh service: aws:cloudwatch emits ContainsSecret

Where it sits

locationListMetrics.Metrics[].Dimensions[].Value
location kindmetadata
data kindscredential sensitive_data pii
emits edgeContainsSecret
serviceCloudWatch/Logs (aws:cloudwatch)

Collection recipe

access moderead_api
operationListMetrics
response pathMetrics[].Dimensions[].Value
encodingstring
params{"Namespace": "\u003cnamespace\u003e"}

Required permissions

cloudwatch:ListMetrics

References

move · open · esc close