Elasticsearch domain principals need review

Review the domain policy’s principals together with actual authentication and network controls.

Description

A domain policy granting broad operations to every principal can allow requests not restricted by other controls to access Elasticsearch indexes and data. Effective access depends on policy effects and conditions, network paths and fine-grained access control.

A wildcard principal does not always permit anonymous access. Some configurations use another authentication model, such as an internal user database; restrict permissions according to the actual model.

Potential impact

  • Unintended principals may perform permitted data reads, changes or deletions.
  • Misuse of excessive permissions can lead to information exposure or service disruption.

Remediation

Narrow allowed principals, actions and resources in AccessPolicies. For IAM principals, configure SigV4 signing and the necessary permission to use the role. For other authentication models, check fine-grained access control and role mappings. Verify network access, HTTPS and actual allowed and denied requests.

Examples

These policy excerpts use the existing AWS::Elasticsearch::Domain format. Replace the account, Region, domain and role ARN with actual values, and supply engine and network settings separately.

Before

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      AccessPolicies:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              AWS: "*"
            Action: es:*
            Resource: arn:aws:es:us-east-1:123456789012:domain/test/*

The policy allows es:* for every AWS principal. Actual access also depends on other policies and authentication and network controls.

After

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      AccessPolicies:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              AWS: arn:aws:iam::123456789012:role/es-access-role
            Action: es:*
            Resource: arn:aws:es:us-east-1:123456789012:domain/test/*

The allowed principal is restricted to one role. es:* remains broad; retain only required actions and review other allowing policies as well.

References