Description
A domain policy granting broad operations to every principal can allow requests not restricted by other controls to access Elasticsearch indexes and data. Effective access depends on policy effects and conditions, network paths and fine-grained access control.
A wildcard principal does not always permit anonymous access. Some configurations use another authentication model, such as an internal user database; restrict permissions according to the actual model.
Potential impact
- Unintended principals may perform permitted data reads, changes or deletions.
- Misuse of excessive permissions can lead to information exposure or service disruption.
Remediation
Narrow allowed principals, actions and resources in AccessPolicies. For IAM principals, configure SigV4 signing and the necessary permission to use the role. For other authentication models, check fine-grained access control and role mappings. Verify network access, HTTPS and actual allowed and denied requests.
Examples
These policy excerpts use the existing AWS::Elasticsearch::Domain format. Replace the account, Region, domain and role ARN with actual values, and supply engine and network settings separately.
Before
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
AccessPolicies:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
AWS: "*"
Action: es:*
Resource: arn:aws:es:us-east-1:123456789012:domain/test/*
The policy allows es:* for every AWS principal. Actual access also depends on other policies and authentication and network controls.
After
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
AccessPolicies:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
AWS: arn:aws:iam::123456789012:role/es-access-role
Action: es:*
Resource: arn:aws:es:us-east-1:123456789012:domain/test/*
The allowed principal is restricted to one role. es:* remains broad; retain only required actions and review other allowing policies as well.