Description
Broad iam:UpdateLoginProfile permission allows changes to other IAM users’ existing console passwords. If the permission is effective for a privileged user and login requirements are met, that user’s permissions can be abused.
The operation changes an existing login profile; it does not grant permission to create one. Changing a password does not bypass MFA or other login restrictions.
Potential impact
- Access through the user account can expose the data and resources within its permissions.
- Unapproved password changes can interrupt legitimate user access.
Remediation
- Remove
iam:UpdateLoginProfilefrom roles that do not need it, and scope necessary access to approved user ARNs. - Limit password administration to help-desk or security administrators, with additional approval for privileged users.
- Review login-profile changes and subsequent sign-ins, and retain existing authentication controls such as MFA.
Examples
These are role-permission excerpts. The required assume_role_policy is omitted; configure it separately so only approved principals can use the role.
Before
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:UpdateLoginProfile",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "inline_policy_run_instances"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Explanation:
- Before: Allows login-profile changes without limiting the target users. Actual login and impact depend on the target account and applicable controls.
- After: Limits the example policy on the same role to EC2 queries. Remove profile-changing access from other policies too, and narrow
ec2:Describe*to required queries.