Description
iam:CreateLoginProfile can set a console password for an IAM user that has no login profile yet. Group members who can do this for a privileged user can create a new access path.
Potential impact
If other sign-in controls permit it, they can gain console access with the target user’s permissions.
Remediation
Remove this permission from groups that do not manage login profiles. Where it is needed, restrict the target users and use dedicated account-administration permissions.
Examples
The examples replace login-profile creation with EC2 describe permissions for the same group. Keep the target user’s other sign-in controls, including MFA.
Before
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreateLoginProfile",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "inline_policy_run_instances"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}