Description
Broad iam:AttachGroupPolicy permissions granted through an IAM group can let members attach powerful managed policies to groups in the same account. If a target group includes the caller, this can expand the permissions of that user and other members.
Policy conditions, explicit denies, permissions boundaries and organization policies can limit the attachment and resulting permissions.
Potential impact
- Members can gain resource access that their work does not require.
- A single group-policy change can affect several IAM users.
Remediation
Remove unnecessary iam:AttachGroupPolicy grants. Where required, restrict Resource to target group ARNs and use iam:PolicyARN conditions to limit the managed policies that can be attached. Use approved administration paths and verify intended operations and denial of unapproved attachments.
Examples
This comparison changes an inline policy on the same group. Check actual group membership separately.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachGroupPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to attach policies across groups.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This replaces that grant with EC2 describe actions. Check for attachment permissions in other policies and restrict describe access to what is needed.