Public access in an SQS queue policy

Limit SQS queue access to required principals and message operations.

Description

Allowing message operations with Principal: "*" in an SQS queue policy can grant unintended principals access to the queue. Applicable conditions and explicit denies also affect effective access.

Potential impact

Depending on the allowed operations, unauthorized messages may be sent or queue messages may be disclosed.

Remediation

Specify required principals and queue ARNs, granting send and receive permissions only where needed. Review other queue policies and IAM permissions as well.

Examples

The examples restrict the same send and receive permissions from public access to a specific account. Attachment settings such as Queues are omitted. Account-level access also requires reviewing permission delegation within that account.

Before

yaml
Resources:
  SampleSQSPolicy:
    Type: AWS::SQS::QueuePolicy
    Properties:
      PolicyDocument:
        Statement:
          - Action:
              - SQS:SendMessage
              - SQS:ReceiveMessage
            Effect: Allow
            Resource: arn:aws:sqs:us-east-2:444455556666:queue2
            Principal: "*"

After

yaml
Resources:
  SampleSQSPolicy:
    Type: AWS::SQS::QueuePolicy
    Properties:
      PolicyDocument:
        Statement:
          - Action:
              - SQS:SendMessage
              - SQS:ReceiveMessage
            Effect: Allow
            Resource: arn:aws:sqs:us-east-2:444455556666:queue2
            Principal:
              AWS:
                - "111122223333"

References