Description
Broad iam:CreateAccessKey permission can let group members create and use access keys for other IAM users. Targeting a more privileged user can lead to privilege escalation.
Potential impact
The new credentials can provide access to data and services allowed for the target user.
Remediation
Remove unnecessary key-creation permission. Limit required administration to approved users, and prefer temporary credentials over long-term keys where possible.
Examples
The examples remove key-creation permission and leave the same group with EC2 describe permissions. This does not revoke keys already issued.
Before
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreateAccessKey",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "inline_policy_run_instances"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}