logo

Database

Aws Anyone Can Subscribe

Description

Detects AWS SNS topics configured with policies that allow unrestricted subscription access. When an SNS topic allows anyone to subscribe and receive messages without proper restrictions, it creates a security risk where sensitive information could be exposed to unauthorized parties.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Checks each SNS topic's access policy for statements that grant 'Allow' permissions

    Identifies if the policy grants both 'SNS:Subscribe' and 'SNS:Receive' actions

    Verifies if the policy has a wildcard or overly permissive Principal without any limiting Conditions

    Reports a vulnerability when an SNS topic's policy allows unrestricted subscription access without appropriate conditions

Severity v4.0

1.3

Low

Method ID

CSPM-CSONB

Technique

CSPM

Target

AWS

Technology

SNS

CWE ID(s)

CWE-306