Description
Broad iam:PutGroupPolicy permissions granted through an IAM group let members add or replace group inline policies. Granting stronger permissions to a group they belong to can enable privilege escalation.
Group policies apply to their IAM user members. User permissions boundaries, organization policies and explicit denies still limit actual access.
Potential impact
- One policy change can give several members unnecessary administrative permissions.
- Unapproved changes can weaken group-based access controls.
Remediation
Remove unnecessary iam:PutGroupPolicy from ordinary groups. Where needed, use a dedicated administration role and an approval process, and restrict Resource to target group ARNs. Review changes, monitor them through CloudTrail, and verify that intended administration works while unapproved changes are blocked.
Examples
This comparison reduces allowed actions in the same group and inline policy.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutGroupPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to add or update inline policies across groups.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now allows only EC2 describe actions. Check for the same modification permission in other policies and review the describe access actually needed.