Description
Broad iam:PutUserPolicy permissions granted to an IAM group let members add or replace inline policies on themselves or other users. This can enable privilege escalation by expanding users’ access when other permission limits do not block it.
Inline policies change the target IAM user’s permissions. They do not automatically remove or bypass boundaries, organization policies or explicit denies.
Potential impact
- Members can grant administrative permissions to themselves or other users without approval.
- Misuse of credentials for users with expanded permissions can cause greater damage.
Remediation
Remove unnecessary iam:PutUserPolicy from ordinary groups. Allow required modifications only through approved administration roles and restrict Resource to target user ARNs. Review policy contents and change events, and verify that intended administration works and unapproved changes are blocked.
Examples
This comparison reduces user-policy modification rights in the same group and inline policy.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants members permission to add or update inline policies across users, including themselves.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now allows only EC2 describe actions. Check for user-modification permissions in other policies and review the describe access needed.