Description
A caller using a role with iam:SetDefaultPolicyVersion can make an existing customer managed policy version the default. A more permissive version of a policy used by that role or another identity the caller controls can provide a path to privilege escalation.
This is distinct from writing new policy contents. Review the existing version and actual policy users; other applicable restrictions and explicit denies remain effective.
Potential impact
- Reverting a shared policy can restore unnecessary permissions for several workloads.
- A role’s access can change outside the approved permission-management process.
Remediation
Remove unnecessary iam:SetDefaultPolicyVersion and limit required work to approved administration roles. Specify target customer managed policy ARNs in Resource and review the version to activate and its users. Check default-version changes through iam:CreatePolicyVersion too, and test that unapproved changes are blocked.
Examples
These excerpts retain the same role and inline policy. Define the omitted trust policy separately in the actual configuration.
Before
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:SetDefaultPolicyVersion",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Callers using this role can change the default version across customer managed policies.
After
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This restricts the statement to EC2 describe actions. Review policy-change permissions through other paths and the describe scope.