Description
Allowing Principal: "*" in an SQS queue policy can grant message operations more broadly than intended. Review Action, Resource, conditions and other policies together. A principal wildcard alone does not grant every reading, deletion or queue-administration operation.
Queues using server-side encryption (SSE) require HTTPS and Signature Version 4 and reject anonymous SendMessage and ReceiveMessage requests. Encryption does not replace access control; authenticated principals and services still need appropriately restricted permissions.
Potential impact
- Broad effective sending permissions can let principals that do not need access inject messages and affect consumer results.
- If reading or deletion is also allowed, message contents can be exposed or messages removed. Actual impact also depends on the application's validation and processing.
Remediation
- Specify required accounts, roles or services in
Principal, required operations inAction, and the actual queue ARN inResource. - For SNS integration, combine the
sns.amazonaws.comservice principal,sqs:SendMessage, the target queue ARN and anaws:SourceArncondition for the approved source topic. - Keep queue encryption enabled and check required KMS permissions for integrated services and conditions or denies in other policies. Test that required delivery succeeds while unapproved principals and sources are denied.
Examples
Supply the ARN of my-queue in the specified account and Region as queue_arn, and the approved source topic ARN as sns_topic_arn. The policy does not create an SNS subscription; configure the subscription and required encryption permissions separately.
Before
- name: example
community.aws.sqs_queue:
name: my-queue
region: ap-southeast-2
policy:
Version: "2012-10-17"
Statement:
Sid: First
Effect: Allow
Principal: "*"
Action: sqs:SendMessage
Resource: "{{ queue_arn }}"
The statement broadly allows principals to send messages. Applicable request requirements and other access controls still matter.
After
- name: example
community.aws.sqs_queue:
name: my-queue
region: ap-southeast-2
policy:
Version: "2012-10-17"
Statement:
Sid: First
Effect: Allow
Principal:
Service: sns.amazonaws.com
Action: sqs:SendMessage
Resource: "{{ queue_arn }}"
Condition:
ArnEquals:
aws:SourceArn: "{{ sns_topic_arn }}"
Sending is restricted to the SNS service with the approved topic as its source. Verify successful delivery from that topic and rejection of requests from other sources.