Description
A role with iam:AttachUserPolicy can attach managed policies to permitted IAM users and expand their permissions. This changes neither the calling role’s own permissions nor its ability to sign in as a target user.
The impact depends on which policies can be attached and how the target user can be used. User permissions boundaries, explicit denies and organization policies still apply.
Potential impact
- Incorrect attachments by an automation role can give users unnecessary administrative permissions.
- Misuse of expanded user permissions can expose information or allow resource changes.
Remediation
Remove iam:AttachUserPolicy where the role does not need it. Limit required administration with target user ARNs in Resource and approved policies in iam:PolicyARN conditions. Review boundaries and change logs, and test intended administration and denial of unapproved attachments.
Examples
These excerpts retain the same role and inline policy. Define the role’s trust policy separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This permits callers using the role to attach managed policies across users.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This narrows the grant to EC2 describe actions. Review other user-administration permissions and the describe access actually needed.