Description
Allowing sts:AssumeRole with Resource: "*" leaves the target roles unrestricted by this policy. Actual assumption must also satisfy the target role’s trust policy and applicable conditions.
Potential impact
Combined with overly broad trust, this can allow switching to an unintended role with greater permissions.
Remediation
List only the required role ARNs in Resource and review the target roles’ trust policies.
Examples
The examples restrict the target to a specific role. Set the role ARN and attached users or groups to match the intended configuration.
Before
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
mypolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: ["sts:AssumeRole"]
Resource: "*"
Users: ["SomeUser"]
After
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: A sample template
Resources:
MyPolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sts:AssumeRole
Resource:
- arn:aws:iam::123456789012:role/ReadOnlyApplicationRole
Groups:
- myexistinggroup1
- !Ref mygroup