Description
A broad SourceArn in a Lambda permission can allow invocation from integrations on unintended API Gateway stages, methods or paths. This service invocation permission is separate from authentication and authorization of API clients.
Broad Lambda permission alone does not make an API anonymously accessible. Check actual integrations, deployments and authentication; intentionally public APIs do not need to be blocked indiscriminately.
Potential impact
- An integration mistakenly attached to another route or stage may invoke the function.
- If client access controls are also inadequate, unwanted invocations and increased costs may result.
Remediation
Restrict SourceArn to the required API, stage, method and resource path, and remove obsolete broad permissions. Limit the calling principal to the API Gateway service and configure the required API-client authentication and authorization separately. Test that intended calls succeed and other routes are rejected.
Examples
The Lambda function definition is omitted. Match function and the ARN’s Region, account and API ID to the actual deployment. The permission logical ID changes between examples; verify that the previous broad permission does not remain.
Before
AWSTemplateFormatVersion: "2010-09-09"
Description: "BatchJobDefinition"
Resources:
s3Permission3:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:InvokeFunction
Principal: apigateway.amazonaws.com
SourceAccount: !Ref "AWS::AccountId"
SourceArn: arn:aws:execute-api:eu-central-1:123456789012:api-id/*/*
The permission broadly covers stages, methods and paths in a particular API. It does not itself remove API-client authentication.
After
AWSTemplateFormatVersion: "2010-09-09"
Description: "BatchJobDefinition"
Resources:
apiPermission:
Type: AWS::Lambda::Permission
Properties:
FunctionName: !GetAtt function.Arn
Action: lambda:InvokeFunction
Principal: apigateway.amazonaws.com
SourceAccount: !Ref "AWS::AccountId"
SourceArn: arn:aws:execute-api:eu-central-1:123456789012:api-id/prod/GET/orders
Invocation is narrowed to GET /orders in the prod stage. API method authentication and authorization checks within the function remain separate requirements.