aws-ebs-snapshot-description-config

Snapshot descriptions are free-form plaintext and can contain misplaced credentials or internal identifiers.

awsmedium service: aws:ebs emits ContainsSecret

Where it sits

locationDescribeSnapshots.Snapshots[].Description
location kindmetadata
data kindscredential sensitive_data
emits edgeContainsSecret
serviceEBS (aws:ebs)

Collection recipe

access moderead_api
operationDescribeSnapshots
response pathSnapshots[].Description
encodingstring
params{"SnapshotIds": ["\u003csnapshot-id\u003e"]}

Required permissions

ec2:DescribeSnapshots

References

move · open · esc close