Description
iam:PassRole permits passing an IAM role to an AWS service. An unrestricted role scope can allow use of a more powerful role when service permissions and the role’s trust policy also permit it.
Potential impact
Attaching a powerful role to a service can let a workload operate with more permissions than intended.
Remediation
Limit Resource to the required IAM role ARNs. Where appropriate, restrict the destination service with iam:PassedToService, and check each role’s permissions and trust policy.
Examples
The examples replace all resources with a specific IAM role. Replace the account ID and role name with an approved role in your environment.
Before
hcl
resource "aws_iam_role_policy" "example" {
name = "test_policy"
role = aws_iam_role.test_role.id
policy = <<-EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"iam:passrole"
],
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}
After
hcl
resource "aws_iam_role_policy" "example" {
name = "test_policy"
role = aws_iam_role.test_role.id
policy = <<-EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": [
"iam:passrole"
],
"Effect": "Allow",
"Resource": "arn:aws:iam::123456789012:role/ExampleWorkloadRole"
}
]
}
EOF
}