Description
Using Allow with Action: "*" and Resource: "*" in an IAM policy grants broad permissions across all actions and resources. Conditions and other limiting policies still affect effective access.
Potential impact
A compromised account or workload with the policy can have a broad impact on data and service configuration.
Remediation
Specify the required actions and resource ARNs. Put actions that do not support resource-level permissions in separate statements with appropriate conditions.
Examples
The examples narrow access to objects in a particular S3 bucket. Replace the bucket and attached groups with actual values, and retain object ACL modification permission only if needed.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
mypolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: ["*"]
Resource: "*"
Groups:
- myexistinggroup1
- !Ref mygroup
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
MyPolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- s3:GetObject
- s3:PutObject
- s3:PutObjectAcl
Resource: arn:aws:s3:::myAWSBucket/*
Groups:
- myexistinggroup1
- !Ref mygroup