Description
glue:UpdateDevEndpoint can change a development endpoint’s public keys and libraries. A group member who gains control of an accessible endpoint can perform work with its attached role’s permissions.
Potential impact
A powerful endpoint role can give group members access to more data and resources than intended.
Remediation
Remove unnecessary update permission or limit it to approved development endpoints. Give the endpoint role only the permissions it needs.
Examples
The examples restrict the same group to EC2 describe actions. Choose permissions for the actual workload and review other attached policies too.
Before
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"glue:UpdateDevEndpoint",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "inline_policy_run_instances"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}