Authentication

Event bus allow cross account access

Description

Amazon EventBridge is a serverless event bus service that allows you to route events between AWS services. Orca has identified that the event bus '{AwsEventBus}' permits access to the following aws accounts: [{AwsEventBus.CrossAccountFindings}].
  • Recommended Mitigation

    Ensure your default event bus permits access only to trusted AWS accounts. More details can be found in <a href="https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-event-bus-perms.html" target="_blank" rel="noopener noreferrer">https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-event-bus-perms.html</a>