aws-redshift-statement-query-text
Submitted SQL text can contain literal passwords, tokens, or sensitive filter values.
Where it sits
| location | redshift-data:DescribeStatement.QueryString |
|---|---|
| location kind | query_text |
| data kinds | credential password sensitive_data |
| emits edge | ContainsSecret |
| service | Redshift (aws:redshift) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | DescribeStatement |
| response path | QueryString |
| encoding | string |
| params | {"Id": "\u003cstatement-id\u003e"} |
Required permissions
redshift-data:DescribeStatement