iam:PassRole allows every role

Limit iam:PassRole to the roles that are needed.

Description

iam:PassRole permits passing an IAM role to an AWS service. An unrestricted role scope can allow use of a more powerful role when service permissions and the role’s trust policy also permit it.

Potential impact

Attaching a powerful role to a service can let a workload operate with more permissions than intended.

Remediation

Limit Resource to the required IAM role ARNs. Where appropriate, restrict the destination service with iam:PassedToService, and check each role’s permissions and trust policy.

Examples

The examples replace all resources with a specific IAM role. Replace the account ID and role name with an approved role in your environment.

Before

hcl
resource "aws_iam_role_policy" "example" {
  name = "test_policy"
  role = aws_iam_role.test_role.id

  policy = <<-EOF
  {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Action": [
          "iam:passrole"
        ],
        "Effect": "Allow",
        "Resource": "*"
      }
    ]
  }
  EOF
}

After

hcl
resource "aws_iam_role_policy" "example" {
  name = "test_policy"
  role = aws_iam_role.test_role.id

  policy = <<-EOF
  {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Action": [
          "iam:passrole"
        ],
        "Effect": "Allow",
        "Resource": "arn:aws:iam::123456789012:role/ExampleWorkloadRole"
      }
    ]
  }
  EOF
}

References