Description
Group members with broad iam:AttachRolePolicy permissions can attach powerful managed policies to roles. They can use the expanded permissions if they can assume a target role or control a workload using it.
Attaching a policy does not change the role’s trust policy or itself grant permission to assume the role. Other permission limits also apply to attachment and subsequent actions.
Potential impact
- Services or user sessions can receive more role permissions than they need.
- An unapproved attachment can affect several workloads that use a role.
Remediation
Remove unnecessary iam:AttachRolePolicy from the group. Where needed, specify target role ARNs in Resource and limit managed policies with iam:PolicyARN conditions. Review role-assumption and workload-control permissions, and test intended operations and denial of unapproved attachments.
Examples
This comparison preserves the same group and inline policy. It reduces permissions for members who do not need to administer roles.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to attach managed policies across roles.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Review role-administration grants in other policies and the describe access actually needed.