Description
Broad iam:SetDefaultPolicyVersion permissions granted through a group let members make an existing customer managed policy version the default. If a policy that applies to them retains an older version granting more permissions, activating it can expand their access.
This action selects an existing version rather than creating new policy contents. Its effect depends on that version and the identities using the policy; other applicable restrictions and explicit denies still apply.
Potential impact
- Permissions removed earlier can become effective again for several identities sharing the policy.
- Switching to an older version can undo an approved reduction in permissions.
Remediation
Remove unnecessary iam:SetDefaultPolicyVersion from ordinary groups and restrict Resource to approved customer managed policy ARNs. Review the version to activate and the identities affected. Also restrict iam:CreatePolicyVersion, which can make a new version default, and test that approved changes work and unapproved changes are blocked.
Examples
This comparison grants managed-policy default-version changes through an inline policy on the same group. It does not change versions of the inline policy itself.
Before
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:SetDefaultPolicyVersion",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Members can select an existing version as default across customer managed policies.
After
resource "aws_iam_group" "example" {
name = "cosmic"
}
resource "aws_iam_group_policy" "example" {
name = "test_inline_policy"
group = aws_iam_group.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Review version-management rights in other policies and the describe scope needed.