IAM role permissions for iam:AttachRolePolicy need review

Restrict managed policies that a role can grant to itself or other roles.

Description

Broad iam:AttachRolePolicy grants can let callers using a role attach powerful managed policies to that same role or other roles. Permissions can expand depending on the allowed targets and roles the caller can use.

Attachment does not automatically bypass explicit denies, permissions boundaries or organization policies. Using another role still requires its trust and caller-permission requirements to be met.

Potential impact

  • An active role can gain administrative permissions it does not need.
  • Changing a shared role can affect several services and user sessions.

Remediation

Remove unnecessary iam:AttachRolePolicy. Where administration is required, restrict Resource to target role ARNs and iam:PolicyARN conditions to approved policies. Review self-modification and other permission limits, and verify intended administration and denial of unapproved attachments.

Examples

These excerpts change an inline policy on the same role. Include the omitted role trust policy separately in the actual deployment configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachRolePolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This permits callers using the role to attach policies across roles.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This replaces the grant with EC2 describe actions while preserving the role’s identity. Review attachment permissions obtained through other policies as well.

References