> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-287.md).

# IAM policies allow exposure of credentials misconfiguration detected in code

## Rule Details

|                        |                           |
| ---------------------- | ------------------------- |
| Cortex AppSec Rule ID  | APPSEC\_AWS\_287          |
| Category - Subcategory | IAM - Credential Exposure |
| Provider               | AWS                       |
| Severity               | HIGH                      |
| Framework              | Terraform, Terraform Plan |

## Impact

This rule is used to verify if Identity and Access Management (IAM) policies are configured in a way that prevents the exposure of credentials. This is paramount for security as exposure of credentials could allow unauthorized users access to sensitive resources and operations. This includes viewing, modifying or deleting data, which can expose the organization to a range of risks, from data breaches to the potential shut down of systems. Therefore, it's crucial to ensure IAM policies are correctly configured to prevent credentials exposure.

## How to Fix

*Resource:* aws\_iam\_policy

* *Arguments:* policy

To fix this issue, you need to review and ensure that the IAM policies do not allow the exposure of credentials. IAM Policies should enforce the least privileges principle.

## The provided Terraform code fixes the identified issue as it strictly follows the least privilege principle, it only provides the resources required permissions to perform "Describe" operations within EC2, and it does not allow any write operations which can possibly change the configuration of the resource leading to potential credentials exposure. \[source,go]

resource "aws\_iam\_policy" "example" { name = "example" path = "/" description = "An example policy"

policy = <\<EOF { "Version": "2012-10-17", "Statement": \[ { "Action": \[ "ec2:Describe\*" ], "Effect": "Allow", "Resource": "\*" } ] } EOF }

## resource "aws\_iam\_role\_policy\_attachment" "test-attach" { role = aws\_iam\_role.test\_role.name policy\_arn = aws\_iam\_policy.example.arn }


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-287.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
