Description
Broad iam:CreatePolicyVersion permissions granted through a group let members create a customer managed policy version and make it the default. Strengthening a policy attached to their group or another identity they can use may enable privilege escalation.
The default version is the operative version. Inline policies are not versioned this way, and setting a new version as default during creation does not require separate iam:SetDefaultPolicyVersion permission.
Potential impact
- Changing a shared policy can expand access for several users or roles.
- Unapproved policy contents can undermine the permission approval process.
Remediation
Remove unnecessary iam:CreatePolicyVersion from ordinary groups and use approved roles for required administration. Restrict Resource to target customer managed policy ARNs. Review iam:SetDefaultPolicyVersion permissions too, check policy contents and users of the policy, and test that unapproved changes are blocked.
Examples
This comparison grants managed-policy version creation through an inline policy on the same group.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreatePolicyVersion",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This permits members to create versions across customer managed policies.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Review version-management rights through other policies and the describe access actually needed.