Description
Callers using a role with iam:CreatePolicyVersion can create a customer managed policy version and activate it as the default. If that policy is attached to the same role or a role used by a workload they control, it can provide a privilege-escalation path.
A new version that is not made default is not operative. Making it default during creation does not require separate iam:SetDefaultPolicyVersion permission; this operation does not version inline policies.
Potential impact
- Permissions can change for several roles and users sharing the policy.
- Workloads can gain unnecessary access to read or modify resources.
Remediation
Remove unnecessary iam:CreatePolicyVersion and limit required work to approved deployment or administration roles. Specify target customer managed policy ARNs in Resource. Review iam:SetDefaultPolicyVersion rights and policy attachments together, and inspect the new version’s permissions and change logs.
Examples
These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreatePolicyVersion",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Callers using this role can create versions across customer managed policies.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This narrows the statement to EC2 describe actions. Review version-management rights through other paths and unnecessary describe permissions.