Description
Callers using a role with iam:PutUserPolicy can expand IAM users’ permissions by adding inline policies or replacing existing ones. This changes the target user’s permissions rather than directly expanding the calling role’s own permissions.
Policy modification does not grant the ability to sign in as the target user. The impact depends on access to that user and other controls, including boundaries, organization policies and explicit denies.
Potential impact
- Incorrect changes by an automation role can give users unnecessary administrative permissions.
- More per-user exceptions can make permissions and changes harder to review.
Remediation
Remove iam:PutUserPolicy where the role does not need it. Where required, use a dedicated administration role and approval process, and restrict Resource to target user ARNs. Review policy contents and change history, and test that intended work succeeds and unapproved changes are blocked.
Examples
These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Callers using this role can add or update inline policies across users.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This narrows the statement to EC2 describe actions. Check that the same user-policy modification permission does not remain in other policies.