Description
glue:UpdateDevEndpoint can change a Glue development endpoint’s public keys or libraries. A principal using a role with this permission may gain control of an accessible endpoint and perform work with its attached role’s permissions.
A powerful endpoint role can create an indirect privilege-escalation path. Effective access still depends on policy resources, conditions, and other permission limits.
Potential impact
- Privilege escalation: control of an endpoint can permit work with greater privileges.
- Data exposure: storage and internal data allowed by the attached role can become accessible.
- Environment modification: a legitimate development environment can be changed to run unintended code.
Remediation
- Remove
glue:UpdateDevEndpointfrom roles that do not manage development endpoints. - Limit required administration to dedicated roles and approved endpoints, and apply least privilege to the endpoint role too.
- Monitor endpoint changes through CloudTrail and an approval process.
Examples
These excerpts compare role permission policies. Configure the trust policy that determines who can use the role separately.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"glue:UpdateDevEndpoint",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "inline_policy_run_instances"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
The after example removes endpoint updates from this policy on the same role and leaves EC2 describe permissions. Choose the permissions needed for the actual work and review other attached policies too.