Description
Combining Effect: Allow, Action: "*" and Resource: "*" can grant very broad permissions. Effective access also depends on policy attachments, conditions, permission boundaries and explicit denies. Identify required actions and resources and remove unnecessary permissions.
Potential impact
If an attached user or role is compromised, its broad permissions may be abused to read, change or delete resources. Actual impact depends on the complete effective permissions.
Remediation
- Narrow access to required APIs and supported resource ARNs. Separate necessary operations that do not support resource-level restrictions and review applicable conditions.
- Inspect attached policies and usage history, then test that required operations succeed and unnecessary operations are denied.
Examples
These alternative policies attach to the same existing role. Set ApplicationRoleName to its actual name and, in the after-example, QueueArn to the queue that role needs to process.
Before
Parameters:
ApplicationRoleName:
Type: String
Resources:
mypolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
Roles:
- !Ref ApplicationRoleName
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: ["*"]
Resource: "*"
The policy allows all actions and resources. Review whether this exceeds the role’s needs.
After
Parameters:
ApplicationRoleName:
Type: String
QueueArn:
Type: String
Resources:
mypolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
Roles:
- !Ref ApplicationRoleName
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- sqs:ReceiveMessage
- sqs:DeleteMessage
Resource: !Ref QueueArn
This statement grants only receiving and deleting messages on the specified queue. Review any other APIs the client needs separately, alongside permissions from other policies.