AssumeRole permission targets all roles

Limit role assumption permissions to required role ARNs.

Description

Allowing sts:AssumeRole with Resource: "*" leaves the target roles unrestricted by this policy. Actual assumption must also satisfy the target role’s trust policy and applicable conditions.

Potential impact

Combined with overly broad trust, this can allow switching to an unintended role with greater permissions.

Remediation

List only the required role ARNs in Resource and review the target roles’ trust policies.

Examples

The examples restrict the target to a specific role. Set the role ARN and attached users or groups to match the intended configuration.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  mypolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: mygrouppolicy
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action: ["sts:AssumeRole"]
            Resource: "*"
      Users: ["SomeUser"]

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
  MyPolicy:
    Type: AWS::IAM::Policy
    Properties:
      PolicyName: mygrouppolicy
      PolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Action:
              - sts:AssumeRole
            Resource:
              - arn:aws:iam::123456789012:role/ReadOnlyApplicationRole
      Groups:
        - myexistinggroup1
        - !Ref mygroup

References