aws-firewallmanager-policy-resource-tag-values

Policy resource-tag selectors are plaintext and can expose sensitive classification values.

awsmedium service: aws:firewallmanager emits ContainsSecret

Where it sits

locationGetPolicy.Policy.ResourceTags[].Value
location kindtag
data kindscredential sensitive_data pii
emits edgeContainsSecret
serviceFirewall Manager (aws:firewallmanager)

Collection recipe

access moderead_api
operationGetPolicy
response pathPolicy.ResourceTags[].Value
encodingstring
params{"PolicyId": "\u003cpolicy-id\u003e"}

Required permissions

fms:GetPolicy

References

move · open · esc close