Description
Broad iam:PutRolePolicy permissions granted through a group let members add or update role inline policies. Members can use expanded permissions if they can assume the modified role or control a workload running with it.
Updating a role policy does not change its trust policy or grant permission to assume it. The target role’s boundaries, organization policies and explicit denies still apply.
Potential impact
- Services using a role can gain resource access they do not need.
- Unapproved role policy changes can affect the execution permissions of several workloads.
Remediation
Remove unnecessary iam:PutRolePolicy from ordinary groups. Perform required changes through approved administration roles and restrict Resource to target role ARNs. Review role-use paths and policy contents, and test that intended work succeeds while unapproved changes are blocked.
Examples
This comparison reduces role-policy modification rights in the same group and inline policy.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to add or update inline policies across roles.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This narrows the statement to EC2 describe actions. Review role-modification rights in other policies and whether the describe actions are needed.