Description
An IAM statement combining Effect: Allow, Action: "*" and Resource: "*" grants permissions for all actions and resources. Even where other policies impose limits, an execution role should contain only the permissions its functions need.
Potential impact
A compromised function or code error may affect the reading, modification or deletion of many AWS resources.
Remediation
Specify the required actions and target resources in provider.iam.role.statements. Grant actions that do not support resource scoping separately, with applicable conditions.
Examples
The statement in these excerpts grants only s3:GetObject for objects in example-bucket. Function definitions and other required permissions, such as logging, are omitted.
Before
yaml
service: service
frameworkVersion: "4"
provider:
name: aws
runtime: nodejs22.x
iam:
role:
statements:
- Effect: Allow
Resource: "*"
Action: "*"
After
yaml
service: service
frameworkVersion: "4"
provider:
name: aws
runtime: nodejs22.x
iam:
role:
statements:
- Effect: Allow
Resource: arn:aws:s3:::example-bucket/*
Action:
- s3:GetObject