IAM role permissions for iam:SetDefaultPolicyVersion need review

Restrict the managed policies whose default versions a role can change.

Description

A caller using a role with iam:SetDefaultPolicyVersion can make an existing customer managed policy version the default. A more permissive version of a policy used by that role or another identity the caller controls can provide a path to privilege escalation.

This is distinct from writing new policy contents. Review the existing version and actual policy users; other applicable restrictions and explicit denies remain effective.

Potential impact

  • Reverting a shared policy can restore unnecessary permissions for several workloads.
  • A role’s access can change outside the approved permission-management process.

Remediation

Remove unnecessary iam:SetDefaultPolicyVersion and limit required work to approved administration roles. Specify target customer managed policy ARNs in Resource and review the version to activate and its users. Check default-version changes through iam:CreatePolicyVersion too, and test that unapproved changes are blocked.

Examples

These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.

Before

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:SetDefaultPolicyVersion",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

Callers using this role can change the default version across customer managed policies.

After

hcl
resource "aws_iam_role" "example" {
  name = "cosmic"
}

resource "aws_iam_role_policy" "example" {
  name = "test_inline_policy"
  role = aws_iam_role.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This restricts the statement to EC2 describe actions. Review policy-change permissions through other paths and the describe scope.

References