Description
Broad iam:AttachUserPolicy permissions granted through a group can let members attach powerful managed policies to themselves or other IAM users. If attachment is allowed and other limits do not block the resulting access, the target user’s permissions can expand.
The attachment changes the target user’s permissions. It does not automatically bypass permissions boundaries or explicit denies.
Potential impact
- Members can increase their own resource access without approval.
- Unnecessary administrative grants to other users can expand an incident’s impact.
Remediation
Remove unnecessary iam:AttachUserPolicy from ordinary groups. Where required, restrict Resource to target user ARNs and use iam:PolicyARN conditions to allow only approved policies. Retain other permission limits and verify intended administration and denial of unapproved attachments.
Examples
This comparison removes policy-attachment permission from an inline policy on the same group. Review actual membership and other attached policies separately.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to attach managed policies across users.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Check that the same attachment permission does not remain through other policies.