Description
Allowing message operations with Principal: "*" in an SQS queue policy can grant unintended principals access to the queue. Applicable conditions and explicit denies also affect effective access.
Potential impact
Depending on the allowed operations, unauthorized messages may be sent or queue messages may be disclosed.
Remediation
Specify required principals and queue ARNs, granting send and receive permissions only where needed. Review other queue policies and IAM permissions as well.
Examples
The examples restrict the same send and receive permissions from public access to a specific account. Attachment settings such as Queues are omitted. Account-level access also requires reviewing permission delegation within that account.
Before
Resources:
SampleSQSPolicy:
Type: AWS::SQS::QueuePolicy
Properties:
PolicyDocument:
Statement:
- Action:
- SQS:SendMessage
- SQS:ReceiveMessage
Effect: Allow
Resource: arn:aws:sqs:us-east-2:444455556666:queue2
Principal: "*"
After
Resources:
SampleSQSPolicy:
Type: AWS::SQS::QueuePolicy
Properties:
PolicyDocument:
Statement:
- Action:
- SQS:SendMessage
- SQS:ReceiveMessage
Effect: Allow
Resource: arn:aws:sqs:us-east-2:444455556666:queue2
Principal:
AWS:
- "111122223333"