IAM role permissions for iam:AddUserToGroup need review

Restrict a role’s authority to change IAM group membership.

Description

A caller using a role with iam:AddUserToGroup can add IAM users to groups in the same account. Adding a user the caller controls to a group that grants greater effective permissions can provide a privilege-escalation path through that user.

A role cannot itself join an IAM group. Adding a user does not change the calling role’s permissions or grant the ability to sign in as that user. Resource limits the target group, so the users to add also need separate approval.

Potential impact

  • Adding an unapproved user to a privileged group can expand access.
  • A compromised administration role can be misused to grant user permissions.

Remediation

Remove unnecessary iam:AddUserToGroup from the role, or restrict Resource to approved target group ARNs when it is required. Review both who can use the role and which users may be added. Check the user’s other permission limits, and test that required membership changes work and unapproved additions are blocked.

Examples

These are excerpts for the same role and inline policy. Define the omitted trust policy separately in the actual configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AddUserToGroup",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants callers using the role permission to add users to groups throughout the account.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Review user-addition permissions in other policies and unnecessary describe access.

References