IAM role permissions for iam:CreatePolicyVersion need review

Limit a role’s managed-policy version creation to approved policies.

Description

Callers using a role with iam:CreatePolicyVersion can create a customer managed policy version and activate it as the default. If that policy is attached to the same role or a role used by a workload they control, it can provide a privilege-escalation path.

A new version that is not made default is not operative. Making it default during creation does not require separate iam:SetDefaultPolicyVersion permission; this operation does not version inline policies.

Potential impact

  • Permissions can change for several roles and users sharing the policy.
  • Workloads can gain unnecessary access to read or modify resources.

Remediation

Remove unnecessary iam:CreatePolicyVersion and limit required work to approved deployment or administration roles. Specify target customer managed policy ARNs in Resource. Review iam:SetDefaultPolicyVersion rights and policy attachments together, and inspect the new version’s permissions and change logs.

Examples

These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreatePolicyVersion",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

Callers using this role can create versions across customer managed policies.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This narrows the statement to EC2 describe actions. Review version-management rights through other paths and unnecessary describe permissions.

References