You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: Incorrect policy used to attempt to enforce MFA
145
+
description: AWS had advised incorrect policies for enforcing MFA which allowed an attacker, if they compromised keys that were protected by this policy, to remove the MFA policy from themselves, or remove the existing MFA device and add their own.
146
+
severity: High
147
+
is_global: True
148
+
group: IAM
149
+
143
150
DOMAIN_NOT_SET_TO_RENEW:
144
151
title: Domain not set to autorenew
145
152
description: This domain will no longer be under your control once it expires and may be taken over by someone else.
# Checking for signatures of the bad MFA policy from https://web.archive.org/web/20170602002425/https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_users-self-manage-mfa-and-creds.html and https://github.com/awsdocs/iam-user-guide/blob/cfe14c674c494d07ba0ab952fe546fdd587da65d/doc_source/id_credentials_mfa_enable_virtual.md#permissions-required
0 commit comments