Description
Callers using a role with broad iam:PutRolePolicy permissions can add or replace inline policies on that role or other roles. They may escalate privileges by expanding the same role’s permissions or modifying a role used by a workload they control.
Modifying another role’s policy alone does not let the caller assume that role. Trust and role-use permissions are separate, and boundaries, organization policies and explicit denies remain in effect.
Potential impact
- Running applications can gain unapproved resource access.
- Policy changes to a reused role can affect several services.
Remediation
Remove unnecessary iam:PutRolePolicy and separate administration into a dedicated role. Where required, restrict Resource to approved target role ARNs. Review self-modification paths and change logs, and verify that intended work succeeds and unapproved changes are blocked.
Examples
These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Callers using this role can add or update inline policies across roles, including the same role.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Check for role-modification rights through other policies and review the describe access actually needed.