SQS policy grants broad permissions to wildcard principals

Limit SQS principals, actions and resources to the producers and consumers that need them.

Description

A wildcard Principal: "*" combined with broad actions such as sqs:* in a queue policy can let unintended identities use the queue. Effective access depends on conditions, explicit denies and other applicable permission controls. Some SQS administrative actions do not support cross-account delegation.

Separate message producers from consumers and grant only the permissions each needs. Restrict queues that do not require public use.

Potential impact

  • Misused message-sending permissions can introduce forged messages or excessive requests that disrupt downstream processing.
  • Effective receive or delete permissions can expose information or remove messages before they are processed.

Remediation

  1. Specify only required accounts, roles or services in Principal, and limit actions to producer or consumer needs.
  2. Set Resource to the target queue ARN and add supported source conditions for service integrations.
  3. Review the existing queue policy and other grants, remove unnecessary permissions, and test legitimate messaging and denial of unapproved access.

Examples

Replace the account ID and role ARN with approved values. Role and application configuration are omitted.

Before

yaml
- name: SQS 큐 생성
  community.aws.sqs_queue:
    name: my-queue1
    region: ap-southeast-1
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: "sqs:*"
          Resource: "*"
          Principal: "*"

This grants broad SQS permissions to a wildcard principal without conditions. Narrow the identities and actions to operational needs.

After

yaml
- name: SQS 큐 생성
  community.aws.sqs_queue:
    name: my-queue1
    region: ap-southeast-1
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: sqs:SendMessage
          Resource: arn:aws:sqs:ap-southeast-1:123456789012:my-queue1
          Principal:
            AWS: arn:aws:iam::123456789012:role/app-producer-role

This statement grants the role only message-sending permission on the specified queue. It does not limit the role's entire permissions or other policies, which also require review.

References