PageSourceSearch

https://www.cloudanix.com/docs/assets/js/047d3a6f.dde968e5.js

js cloudanix.com collected 2026-10-02 10:15:10 UTC 11,610 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkcloudanix_dotcom_docs_temp=self.webpackChunkcloudanix_dotcom_docs_temp||[]).push([["1195"],{938465(e,n,s){s.r(n),s.d(n,{metadata:()=>t,default:()=>u,frontMatter:()=>i,contentTitle:()=>r,toc:()=>l,assets:()=>a});var t=JSON.parse('{"id":"aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access_remediation","title":"Event Bus Cross Account Access Remediation","description":"Step-by-step remediation instructions for AWS CloudWatch event bus cross account access misconfiguration using Console, CLI, Python, Terraform.","source":"@site/docs/aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access_remediation.mdx","sourceDirName":"aws/audit/cloudwatchmonitoring/rules","slug":"/aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access_remediation","permalink":"/docs/aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access_remediation","draft":false,"unlisted":false,"editUrl":"https://github.com/Cloudanix/cloudanix-dotcom-docs/edit/main/docs/aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access_remediation.mdx","tags":[],"version":"current","frontMatter":{"title":"Event Bus Cross Account Access Remediation","sidebar_label":"Event Bus Cross Account Access Remediation","description":"Step-by-step remediation instructions for AWS CloudWatch event bus cross account access misconfiguration using Console, CLI, Python, Terraform."},"sidebar":"docsSidebar","previous":{"title":"EventBus Should Not Allow Cross Account Access","permalink":"/docs/aws/audit/cloudwatchmonitoring/rules/event_bus_cross_account_access"},"next":{"title":"Event Bus Should Not Be Exposed","permalink":"/docs/aws/audit/cloudwatchmonitoring/rules/event_bus_exposed"}}'),o=s(474848),c=s(28453);let i={title:"Event Bus Cross Account Access Remediation",sidebar_label:"Event Bus Cross Account Access Remediation",description:"Step-by-step remediation instructions for AWS CloudWatch event bus cross account access misconfiguration using Console, CLI, Python, Terraform."},r,a={},l=[{value:"Triage and Remediation",id:"triage-and-remediation",level:3},{value:"Remediation",id:"remediation",level:3}];function d(e){let n={code:"code",h1:"h1",h3:"h3",li:"li",ol:"ol",p:"p",pre:"pre",...(0,c.R)(),...e.components},{Accordion:s,AccordionGroup:t,Tab:i,Tabs:r}=n;return s||h("Accordion",!0),t||h("AccordionGroup",!0),i||h("Tab",!0),r||h("Tabs",!0),(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(n.h3,{id:"triage-and-remediation",children:"Triage and Remediation"}),"\n",(0,o.jsx)(r,{children:(0,o.jsxs)(i,{title:"Remediation",children:[(0,o.jsx)(n.h3,{id:"remediation",children:"Remediation"}),(0,o.jsxs)(t,{children:[(0,o.jsxs)(s,{title:"Using Console",defaultOpen:"true",children:[(0,o.jsx)(n.p,{children:'To remediate the "EventBus Should Not Allow Cross Account Access" misconfiguration in AWS using the AWS console, follow these steps:'}),(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsx)(n.li,{children:"Login to the AWS Management Console."}),"\n",(0,o.jsx)(n.li,{children:"Navigate to the Amazon EventBridge service."}),"\n",(0,o.jsx)(n.li,{children:"Select the Event Bus that is allowing cross-account access."}),"\n",(0,o.jsx)(n.li,{children:'Click on the "Permissions" tab.'}),"\n",(0,o.jsx)(n.li,{children:'In the "Event bus policies" section, click on the "Edit" button.'}),"\n",(0,o.jsx)(n.li,{children:"Remove any statements that grant cross-account access to the Event Bus."}),"\n",(0,o.jsx)(n.li,{children:"Add a new statement that only allows access from the AWS account(s) that require access to the Event Bus."}),"\n",(0,o.jsx)(n.li,{children:'Click on the "Save" button to apply the changes.'}),"\n"]}),(0,o.jsx)(n.p,{children:"After following these steps, the Event Bus will no longer allow cross-account access and will only allow access from the specified AWS account(s)."}),(0,o.jsx)(n.h1,{id:""})]}),(0,o.jsxs)(s,{title:"Using CLI",children:[(0,o.jsx)(n.p,{children:'To remediate the "EventBus Should Not Allow Cross Account Access" misconfiguration in AWS using AWS CLI, follow these steps:'}),(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Open your terminal or command prompt and ensure that you have the AWS CLI installed and configured with the appropriate credentials."}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Run the following command to list all the Amazon EventBridge event buses in your AW
1S account:"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{children:"aws events list-event-buses\n"})}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Identify the event bus that is allowing cross-account access."}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Run the following command to modify the event bus policy and restrict cross-account access:"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{children:'aws events put-policy --event-bus-name <event-bus-name> --policy \'{"Statement":[{"Sid":"RestrictCrossAccountAccess","Effect":"Deny","Principal":"*","Action":"events:PutEvents","Resource":"arn:aws:events:<region>:<account-id>:event-bus/<event-bus-name>"}]}\'\n'})}),"\n",(0,o.jsxs)(n.p,{children:["Replace ",(0,o.jsx)(n.code,{children:"<event-bus-name>"})," with the name of the event bus that is allowing cross-account access, ",(0,o.jsx)(n.code,{children:"<region>"})," with the AWS region where the event bus is located, and ",(0,o.jsx)(n.code,{children:"<account-id>"})," with your AWS account ID."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Verify that the policy has been updated by running the following command:"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{children:"aws events describe-event-bus --name <event-bus-name>\n"})}),"\n",(0,o.jsxs)(n.p,{children:["The output should show the updated policy with the ",(0,o.jsx)(n.code,{children:"Deny"})," statement."]}),"\n"]}),"\n",(0,o.jsxs)(n.li,{children:["\n",(0,o.jsx)(n.p,{children:"Repeat steps 3-5 for any other event buses that are allowing cross-account access."}),"\n"]}),"\n"]}),(0,o.jsx)(n.p,{children:'By following these steps, you have successfully remediated the "EventBus Should Not Allow Cross Account Access" misconfiguration in AWS using AWS CLI.'})]}),(0,o.jsxs)(s,{title:"Using Python",children:[(0,o.jsx)(n.p,{children:'To remediate the misconfiguration "EventBus Should Not Allow Cross Account Access" in AWS, you can follow the below steps in Python:'}),(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsx)(n.li,{children:"Create a new EventBridge event bus policy that allows access only to the specific AWS account that should have access to the event bus."}),"\n"]}),(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-python",children:'import boto3\nimport json\n\neventbridge = boto3.client(\'events\')\n\naccount_id = boto3.client(\'sts\').get_caller_identity().get(\'Account\')\n\npolicy = {\n    "Version": "2012-10-17",\n    "Statement": [\n        {\n            "Sid": "AllowAccountAccess",\n            "Effect": "Allow",\n            "Principal": {\n                "AWS": f"arn:aws:iam::{account_id}:root"\n            },\n            "Action": "events:*",\n            "Resource": "arn:aws:events:us-east-1:<account_id>:event-bus/default"\n        }\n    ]\n}\n\npolicy_json = json.dumps(policy)\n\neventbridge.put_permission(\n    Action=\'events:PutEvents\',\n    Principal=\'*\',\n    StatementId=\'AllowAccountAccess\',\n    Condition={\n        \'ArnEquals\': {\n            \'aws:SourceArn\': f\'arn:aws:events:us-east-1:<account_id>:event-bus/default\'\n        }\n    }\n)\n\neventbridge.put_event_bus_policy(\n    EventBusName=\'default\',\n    Policy=policy_json\n)\n'})}),(0,o.jsxs)(n.ol,{start:"2",children:["\n",(0,o.jsx)(n.li,{children:"Remove any existing event bus policies that allow cross-account access."}),"\n"]}),(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-python",children:'policy = {\n    "Version": "2012-10-17",\n    "Statement": [\n        {\n            "Sid": "DenyCrossAccountAccess",\n            "Effect": "Deny",\n            "Principal": "*",\n            "Action": "events:*",\n            "Resource": "arn:aws:events:us-east-1:<account_id>:event-bus/default",\n            "Condition": {\n                "StringNotEquals": {\n                    "aws:PrincipalAccount": "<account_id>"\n                }\n            }\n        }\n    ]\n}\n\npolicy_json = json.dumps(policy)\n\neventbridge.put_event_bus_policy(\n    EventBusName=\'default\',\n    Policy=policy_json\n)\n'})}),(0,o.jsxs)(n.ol,{start:"3",children:["\n",(0,o.jsx)(n.li,{children:"Verify that the event bus policy now only allows access to the specific AWS account that should have access to the event bus."}),"\n"]}),(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-python",children:"policy = eventbridge.describe_event_bus(\n    Name='default'\n)['Policy']\n\nprint(policy)\n"})}),(0,o.jsx)(n.p,{children:'This should remediate the "EventBus Should Not Allow Cross A
1ccount Access" misconfiguration in AWS.'})]}),(0,o.jsxs)(s,{title:"Using Terraform",children:[(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-hcl",children:'resource "aws_cloudwatch_event_bus" "this" {\n  name = "EVENT_BUS_NAME" # replace with your event bus name\n}\n\n# Secure example: only allow a specific trusted AWS account (or remove this block entirely\n# if you do not want any cross-account access).\nresource "aws_cloudwatch_event_permission" "trusted_account" {\n  statement_id   = "ALLOW_TRUSTED_ACCOUNT"          # replace with a unique SID\n  principal      = "TRUSTED_AWS_ACCOUNT_ID"         # replace with the allowed AWS account ID\n  action         = "events:PutEvents"\n  event_bus_name = aws_cloudwatch_event_bus.this.name\n}\n'})}),(0,o.jsxs)(n.p,{children:["To match the CLI remediation (",(0,o.jsx)(n.code,{children:"aws events remove-permission"}),"), remove from your Terraform configuration any ",(0,o.jsx)(n.code,{children:"aws_cloudwatch_event_permission"})," resources whose ",(0,o.jsx)(n.code,{children:"principal"})," represents unintended or unknown accounts (including ",(0,o.jsx)(n.code,{children:'"*"'}),"); on ",(0,o.jsx)(n.code,{children:"terraform apply"})," Terraform will delete those permissions from the event bus policy."]}),(0,o.jsx)(n.p,{children:"This change is destructive to those permissions and may break existing cross-account event delivery workflows\u2014review carefully before applying."}),(0,o.jsxs)(n.p,{children:["Verification: ",(0,o.jsx)(n.code,{children:"terraform plan"})," should show the unwanted ",(0,o.jsx)(n.code,{children:"aws_cloudwatch_event_permission"})," resources as ",(0,o.jsx)(n.code,{children:"- destroy"})," (or their ",(0,o.jsx)(n.code,{children:"principal"})," narrowed to only the trusted IDs/ARNs), with no changes to the ",(0,o.jsx)(n.code,{children:"aws_cloudwatch_event_bus"})," itself."]})]})]})]})})]})}function u(e={}){let{wrapper:n}={...(0,c.R)(),...e.components};return n?(0,o.jsx)(n,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}function h(e,n){throw Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}},28453(e,n,s){s.d(n,{R:()=>i,x:()=>r});var t=s(296540);let o={},c=t.createContext(o);function i(e){let n=t.useContext(c);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:i(e.components),t.createElement(c.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.