Added two dangerous policies to evaluate-iam-role.sh

This commit is contained in:
mgeeky 2019-12-06 09:57:53 +01:00
parent 7b10ba1c08
commit fb01387ed3

View File

@ -32,7 +32,8 @@ known_potentially_dangerous_permissions=(
) )
known_dangerous_permissions=( known_dangerous_permissions=(
"*:*" "\*:\*"
"iam:\*"
"iam:CreatePolicyVersion" "iam:CreatePolicyVersion"
"iam:SetDefaultPolicyVersion" "iam:SetDefaultPolicyVersion"
"iam:PassRole" "iam:PassRole"