fix(aws): findings in IAM policies were not reported (#5560)

This commit is contained in:
Kay Agahd
2024-10-29 14:29:29 -05:00
committed by GitHub
parent e6053ce218
commit ec69d8073a
6 changed files with 9 additions and 3 deletions
@@ -20,6 +20,5 @@ class iam_aws_attached_policy_no_administrative_privileges(Check):
if check_admin_access(policy.document):
report.status = "FAIL"
report.status_extended = f"{policy.type} policy {policy.name} is attached and allows '*:*' administrative privileges."
break
findings.append(report)
return findings
@@ -20,6 +20,5 @@ class iam_customer_attached_policy_no_administrative_privileges(Check):
if check_admin_access(policy.document):
report.status = "FAIL"
report.status_extended = f"{policy.type} policy {policy.name} is attached and allows '*:*' administrative privileges."
break
findings.append(report)
return findings
@@ -20,6 +20,5 @@ class iam_customer_unattached_policy_no_administrative_privileges(Check):
if check_admin_access(policy.document):
report.status = "FAIL"
report.status_extended = f"{policy.type} policy {policy.name} is unattached and allows '*:*' administrative privileges."
break
findings.append(report)
return findings
@@ -34,6 +34,7 @@ class Test_iam_aws_attached_policy_no_administrative_privileges_test:
check = iam_aws_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "AdministratorAccess":
assert result.status == "FAIL"
@@ -73,6 +74,7 @@ class Test_iam_aws_attached_policy_no_administrative_privileges_test:
check = iam_aws_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "IAMUserChangePassword":
assert result.status == "PASS"
@@ -115,6 +117,7 @@ class Test_iam_aws_attached_policy_no_administrative_privileges_test:
check = iam_aws_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 2, f"Expected 2 results, but got {len(results)}"
for result in results:
if result.resource_id == "IAMUserChangePassword":
assert result.status == "PASS"
@@ -42,6 +42,7 @@ class Test_iam_customer_attached_policy_no_administrative_privileges_test:
check = iam_customer_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "FAIL"
@@ -84,6 +85,7 @@ class Test_iam_customer_attached_policy_no_administrative_privileges_test:
check = iam_customer_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "PASS"
@@ -141,6 +143,7 @@ class Test_iam_customer_attached_policy_no_administrative_privileges_test:
check = iam_customer_attached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 2, f"Expected 2 results, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "PASS"
@@ -39,6 +39,7 @@ class Test_iam_customer_unattached_policy_no_administrative_privileges_test:
check = iam_customer_unattached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "FAIL"
@@ -78,6 +79,7 @@ class Test_iam_customer_unattached_policy_no_administrative_privileges_test:
check = iam_customer_unattached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 1, f"Expected 1 result, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "PASS"
@@ -129,6 +131,7 @@ class Test_iam_customer_unattached_policy_no_administrative_privileges_test:
check = iam_customer_unattached_policy_no_administrative_privileges()
results = check.execute()
assert len(results) == 2, f"Expected 2 results, but got {len(results)}"
for result in results:
if result.resource_id == "policy1":
assert result.status == "PASS"