Description
Broad iam:AttachRolePolicy grants can let callers using a role attach powerful managed policies to that same role or other roles. Permissions can expand depending on the allowed targets and roles the caller can use.
Attachment does not automatically bypass explicit denies, permissions boundaries or organization policies. Using another role still requires its trust and caller-permission requirements to be met.
Potential impact
- An active role can gain administrative permissions it does not need.
- Changing a shared role can affect several services and user sessions.
Remediation
Remove unnecessary iam:AttachRolePolicy. Where administration is required, restrict Resource to target role ARNs and iam:PolicyARN conditions to approved policies. Review self-modification and other permission limits, and verify intended administration and denial of unapproved attachments.
Examples
These excerpts change an inline policy on the same role. Include the omitted role trust policy separately in the actual deployment configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This permits callers using the role to attach policies across roles.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This replaces the grant with EC2 describe actions while preserving the role’s identity. Review attachment permissions obtained through other policies as well.