aws-firewallmanager-policy-resource-tag-values
Policy resource-tag selectors are plaintext and can expose sensitive classification values.
Where it sits
| location | GetPolicy.Policy.ResourceTags[].Value |
| location kind | tag |
| data kinds | credential sensitive_data pii |
| emits edge | ContainsSecret |
| service | Firewall Manager (aws:firewallmanager) |
Collection recipe
| access mode | read_api |
| operation | GetPolicy |
| response path | Policy.ResourceTags[].Value |
| encoding | string |
| params | {"PolicyId": "\u003cpolicy-id\u003e"} |
Required permissions
References