Added two dangerous policies to evaluate-iam-role.sh

This commit is contained in:
mgeeky 2019-12-06 09:57:53 +01:00
parent 7b10ba1c08
commit fb01387ed3
1 changed files with 2 additions and 1 deletions

View File

@ -32,7 +32,8 @@ known_potentially_dangerous_permissions=(
)
known_dangerous_permissions=(
"*:*"
"\*:\*"
"iam:\*"
"iam:CreatePolicyVersion"
"iam:SetDefaultPolicyVersion"
"iam:PassRole"