Skip to content

fix(query): fix fn for iam_policy_grants_full_permissions#7500

Merged
cx-miguel-dasilva merged 7 commits into
Checkmarx:masterfrom
cx-romeu-silva:AST-98288
Jul 1, 2025
Merged

fix(query): fix fn for iam_policy_grants_full_permissions#7500
cx-miguel-dasilva merged 7 commits into
Checkmarx:masterfrom
cx-romeu-silva:AST-98288

Conversation

@cx-romeu-silva

@cx-romeu-silva cx-romeu-silva commented Jun 17, 2025

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes

  • IAM policies defined using aws_iam_policy_document where both actions and resources contain "*" are not identified.

Proposed Changes

  • Add a CxPolicy to detect aws_iam_policy_document data blocks where both actions and resources include "*".

I submit this contribution under the Apache-2.0 license.

@cx-romeu-silva cx-romeu-silva requested a review from a team as a code owner June 17, 2025 15:03
@github-actions github-actions Bot added community Community contribution query New query feature aws PR related with AWS Cloud labels Jun 17, 2025
@cx-romeu-silva cx-romeu-silva changed the title fix(query): FN for iam_policy_grants_full_permissions fix(query): fix fn for iam_policy_grants_full_permissions Jun 17, 2025

@cx-artur-ribeiro cx-artur-ribeiro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cx-miguel-dasilva cx-miguel-dasilva merged commit 82e79fd into Checkmarx:master Jul 1, 2025
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aws PR related with AWS Cloud community Community contribution query New query feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants