Property
Languagehcl
Severitylow
CWECWE-200: Exposure of Sensitive Information to an Unauthorized Actor
OWASPA01:2021 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The IAM policy grants permissions that can make AWS resources publicly accessible or expose them to unintended users. This includes actions like setting resource policies or managing permissions without proper restrictions.

Impact#

If exploited, attackers could gain unauthorized access to sensitive resources, data, or infrastructure. This may lead to data leaks, unauthorized modifications, or complete compromise of critical AWS services in your account.