IAM role can escalate privileges through glue:UpdateDevEndpoint

Limit an IAM role’s permission to modify Glue development endpoints.

Description

glue:UpdateDevEndpoint can change a Glue development endpoint’s public keys or libraries. A principal using a role with this permission may gain control of an accessible endpoint and perform work with its attached role’s permissions.

A powerful endpoint role can create an indirect privilege-escalation path. Effective access still depends on policy resources, conditions, and other permission limits.

Potential impact

  • Privilege escalation: control of an endpoint can permit work with greater privileges.
  • Data exposure: storage and internal data allowed by the attached role can become accessible.
  • Environment modification: a legitimate development environment can be changed to run unintended code.

Remediation

  • Remove glue:UpdateDevEndpoint from roles that do not manage development endpoints.
  • Limit required administration to dedicated roles and approved endpoints, and apply least privilege to the endpoint role too.
  • Monitor endpoint changes through CloudTrail and an approval process.

Examples

These excerpts compare role permission policies. Configure the trust policy that determines who can use the role separately.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "glue:UpdateDevEndpoint",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "inline_policy_run_instances"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

The after example removes endpoint updates from this policy on the same role and leaves EC2 describe permissions. Choose the permissions needed for the actual work and review other attached policies too.

References