Description
A wildcard Principal: "*" combined with broad actions such as sqs:* in a queue policy can let unintended identities use the queue. Effective access depends on conditions, explicit denies and other applicable permission controls. Some SQS administrative actions do not support cross-account delegation.
Separate message producers from consumers and grant only the permissions each needs. Restrict queues that do not require public use.
Potential impact
- Misused message-sending permissions can introduce forged messages or excessive requests that disrupt downstream processing.
- Effective receive or delete permissions can expose information or remove messages before they are processed.
Remediation
- Specify only required accounts, roles or services in
Principal, and limit actions to producer or consumer needs. - Set
Resourceto the target queue ARN and add supported source conditions for service integrations. - Review the existing queue policy and other grants, remove unnecessary permissions, and test legitimate messaging and denial of unapproved access.
Examples
Replace the account ID and role ARN with approved values. Role and application configuration are omitted.
Before
- name: SQS 큐 생성
community.aws.sqs_queue:
name: my-queue1
region: ap-southeast-1
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: "sqs:*"
Resource: "*"
Principal: "*"
This grants broad SQS permissions to a wildcard principal without conditions. Narrow the identities and actions to operational needs.
After
- name: SQS 큐 생성
community.aws.sqs_queue:
name: my-queue1
region: ap-southeast-1
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: sqs:SendMessage
Resource: arn:aws:sqs:ap-southeast-1:123456789012:my-queue1
Principal:
AWS: arn:aws:iam::123456789012:role/app-producer-role
This statement grants the role only message-sending permission on the specified queue. It does not limit the role's entire permissions or other policies, which also require review.