Impact: repository revisions before v1.3.2 documented a weekly integration IAM policy that allowed role lifecycle operations on af-e2e-* roles without sufficient boundary or trust restrictions. Code running with that documented principal could create persistent higher-privilege roles in the sandbox account.
Patched in v1.3.2: unnecessary inline-policy and trust-update permissions were removed and the guide was updated.
Remediation: replace any deployed weekly integration IAM policy with the v1.3.2 or later template.
Impact: repository revisions before v1.3.2 documented a weekly integration IAM policy that allowed role lifecycle operations on af-e2e-* roles without sufficient boundary or trust restrictions. Code running with that documented principal could create persistent higher-privilege roles in the sandbox account.
Patched in v1.3.2: unnecessary inline-policy and trust-update permissions were removed and the guide was updated.
Remediation: replace any deployed weekly integration IAM policy with the v1.3.2 or later template.